Vulnerability Details CVE-2013-0078
The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 56.8%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2013-0078
-
cpe:2.3:a:microsoft:windows_defender:-
-
cpe:2.3:a:microsoft:windows_defender:1.1.23060.3001
-
cpe:2.3:a:microsoft:windows_defender:4.18.23100.2009
-
cpe:2.3:o:microsoft:windows_8:-
-
cpe:2.3:o:microsoft:windows_rt:-