SB2013051501 - Permissions, Privileges, and Access Controls in Microsoft Windows Essentials



SB2013051501 - Permissions, Privileges, and Access Controls in Microsoft Windows Essentials

Published: May 15, 2013 Updated: August 11, 2020

Security Bulletin ID SB2013051501
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-0096)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability." Per: http://technet.microsoft.com/en-us/security/bulletin/ms13-045 'There is no update available for Windows Essentials 2011. See update FAQ for details.'


Remediation

Install update from vendor's website.