The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
Published May 24, 2013 ·Due Apr 18, 2022
7.8
HIGHCVSS 3.1
EPSS 39.32%
Description
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
Affected products
No data.
- n/a
- n/a
- n/a
- n/a
- n/a
- r2
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
Date Added
Mar 28, 2022
Patch Due
Apr 18, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 39.32% (0.39318) | 98.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 39.32% (0.39318) | 98.42th | v5 (v2026.06.15) |
| Apr 23, 2026 | 70.63% (0.70632) | 98.70th | v4 (v2025.03.14) |
| Dec 28, 2025 | 69.19% (0.69191) | 98.58th | v4 (v2025.03.14) |
| Dec 27, 2025 | 73.02% (0.73025) | 98.74th | v4 (v2025.03.14) |
| Oct 28, 2025 | 69.19% (0.69191) | 98.56th | v4 (v2025.03.14) |
| Oct 27, 2025 | 73.02% (0.73025) | 98.72th | v4 (v2025.03.14) |
| Oct 1, 2025 | 69.19% (0.69191) | 98.60th | v4 (v2025.03.14) |
| Sep 26, 2025 | 73.02% (0.73025) | 98.75th | v4 (v2025.03.14) |
| Aug 17, 2025 | 74.23% (0.74231) | 98.78th | v4 (v2025.03.14) |
| Mar 30, 2025 | 67.94% (0.67944) | 98.47th | v4 (v2025.03.14) |
| Mar 17, 2025 | 70.11% (0.70109) | 98.57th | v4 (v2025.03.14) |
| Feb 20, 2025 | 62.02% (0.62021) | 98.03th | v3 (v2023.03.01) |
| Dec 22, 2024 | 74.94% (0.74942) | 98.36th | v3 (v2023.03.01) |
| Dec 17, 2024 | 70.06% (0.70061) | 98.20th | v3 (v2023.03.01) |
| Dec 12, 2024 | 83.07% (0.83074) | 98.55th | v3 (v2023.03.01) |
| Jul 10, 2024 | 82.86% (0.82861) | 98.46th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.06% (0.00061) | 26.19th | v3 (v2023.03.01) |
| Oct 17, 2023 | 0.06% (0.00061) | 24.18th | v3 (v2023.03.01) |
| Aug 28, 2023 | 0.07% (0.00074) | 30.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00061) | 23.68th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.04% (0.06037) | 90.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.04% (0.06037) | 89.69th | v2 (v2022.01.01) |
| Feb 8, 2022 | 6.04% (0.06037) | 77.67th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.00% (0.03001) | 64.40th | v2 (v2022.01.01) |
References (15)
- http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0090.html mailing-listx_refsource_FULLDISCBroken Link
- http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0094.html mailing-listx_refsource_FULLDISCBroken Link
- http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0006.html mailing-listx_refsource_FULLDISCBroken Link
- http://secunia.com/advisories/53435 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://twitter.com/taviso/statuses/309157606247768064 x_refsource_MISCExploit
- http://twitter.com/taviso/statuses/335557286657400832 x_refsource_MISCNot Applicable
- http://www.computerworld.com/s/article/9239477 x_refsource_MISCBroken Link
- http://www.exploit-db.com/exploits/25611/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.osvdb.org/93539 vdb-entryx_refsource_OSVDBBroken Link
- http://www.reddit.com/r/netsec/comments/1eqh66/0day_windows_kernel_epathobj_vulnerability/ x_refsource_MISCExploitIssue Tracking
- http://www.theverge.com/2013/5/23/4358400/google-engineer-bashes-microsoft-discloses-windows-flaw x_refsource_MISCPress/Media Coverage
- http://www.us-cert.gov/ncas/alerts/TA13-190A third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-053 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17360 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3660 government-resourceUS Government Resource
Change history (0)
No recorded changes yet.