Vigil@nce - Windows: multiple vulnerabilities of win32k.sys
April 2013 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can use several vulnerabilities of win32k.sys of
Windows.
Impacted products: Windows 2003, Windows 2008, Microsoft Windows
2012, Windows 7, Windows 8, Windows RT, Windows Vista, Windows XP
Severity: 2/4
Creation date: 09/04/2013
DESCRIPTION OF THE VULNERABILITY
Several vulnerabilities were announced in Windows.
An attacker can manipulate an object, in order to escalate his
privileges. [severity:2/4; BID-58858, CVE-2013-1283]
An attacker can use a malicious OpenType font, in order to restart
the system. [severity:2/4; BID-58853, CVE-2013-1291]
An attacker can manipulate an object, in order to escalate his
privileges. [severity:2/4; BID-58859, CVE-2013-1292]
An attacker can mount a malicious NTFS device, in order to
escalate his privileges. [severity:2/4; BID-58860, CVE-2013-1293]
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
http://vigilance.fr/vulnerability/Windows-multiple-vulnerabilities-of-win32k-sys-12641