High Risk Vulnerability in Microsoft Windows=20
18 March 2013
Andy Davis of NCC Group has discovered a High risk vulnerability in Microso=
ft Windows=20
Impact: Windows USB RNDIS driver kernel pool overflow. Exploitation would r=
esult in local privilege escalation
Versions affected: Microsoft Windows (all current versions apart from RT)=
=20
Details of the patch can be found at the following URL:
http://technet.microsoft.com/en-us/security/bulletin/ms13-027
NCC Group is going to withhold details of this flaw for three months. This =
three month window will allow users the time needed to apply the patch befo=
re the details are released to the general public. This reflects the NCC Gr=
oup approach to responsible disclosure.
NCC Group Research
http://www.nccgroup.com/research
For more information please visit <a href=3D"http://www.mimecast.com">http:=
//www.mimecast.com<br>
This email message has been delivered safely and archived online by Mimecas=
t.
</a>