Microsoft Windows 7 Defender Improper Pathname Vulnerability
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
This is an elevation of privilege vulnerability. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.
Impact
- Elevation of Privilege
System / Technologies affected
- Windows Defender for Windows 7 (x86)
- Windows Defender for Windows 7 (x64)
- Windows Defender when installed on Windows Server 2008 R2 (x64)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS13-058
Vulnerability Identifier
Source
Related Link
Share with