Short Name |
HTTP:STC:ADOBE:2013-5065-PDF |
---|---|
Severity |
Critical |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Adobe Acrobat Reader CVE-2013-5065 Malicious Dropper |
Release Date |
2013/12/03 |
Update Number |
2324 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects the pdf dropper that is being used in-the-wild to exploit a known privilege escalation vulnerability against Windows XP and Windows Server 2003. Successful exploitation could lead to arbitrary code execution in Kernel mode.
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.