Microsoft Windows Theme File CVE-2013-0810 Remote Code Execution Vulnerability
BID:62176
Info
Microsoft Windows Theme File CVE-2013-0810 Remote Code Execution Vulnerability
| Bugtraq ID: | 62176 |
| Class: | Unknown |
| CVE: |
CVE-2013-0810 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 21 2013 12:15AM |
| Credit: | Eduardo Prado, working with VeriSign iDefense Labs |
| Vulnerable: |
Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Theme File CVE-2013-0810 Remote Code Execution Vulnerability
Microsoft Windows is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the currently logged-in user, which can lead to a complete compromise of the affected computer.
Microsoft Windows is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the currently logged-in user, which can lead to a complete compromise of the affected computer.
Exploit / POC
Microsoft Windows Theme File CVE-2013-0810 Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploit is available:
Solution / Fix
Microsoft Windows Theme File CVE-2013-0810 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Windows Theme File CVE-2013-0810 Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)