CVE Vulnerabilities

CVE-2013-3154

Published: Jul 10, 2013 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka Microsoft Windows 7 Defender Improper Pathname Vulnerability.

Affected Software

Name Vendor Start Version End Version
Windows_defender Microsoft * *

References