CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS13-034 | Vulnerability in Microsoft Antimalware Client Could Allow Elevation of Privilege (2823482) | Windows Defender | Critical | 10-04-2013 |
Technical Information
Brief overview of the risk:
This security update resolves a privately reported vulnerability in the Microsoft Antimalware Client. The vulnerability could allow elevation of privilege due to the pathnames used by the Microsoft Antimalware Client. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system.
Detailed Information on the risk:
This is an elevation of privilege vulnerability. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.Further information on this exploit is available at : MS13-034