CVE-2013-3956 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 7.8% (pctl 94)
Patch early
A public exploit exists.
Description
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted 0x143B6B IOCTL call.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 7.8% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-07-31 |
| Last modified | 2026-06-16 |
Affected (7)
| Vendor | Product |
|---|---|
| microsoft | windows 2003 server |
| microsoft | windows 7 |
| microsoft | windows 8 |
| microsoft | windows server 2008 |
| microsoft | windows vista |
| microsoft | windows xp |
| novell | client |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Novell Client 2 SP3 - 'nicm.sys 3.1.11.0' Local Privilege Escalation | 2013-07-29 |
| exploit-db | Novell Client 2 SP3 - 'nicm.sys' Local Privilege Escalation (Metasploit) | 2013-06-26 |
References
- http://pastebin.com/GB4iiEwR
- http://www.exploit-db.com/exploits/26452
- http://www.exploit-db.com/exploits/27191
- http://www.novell.com/support/kb/doc.php?id=7012497
- http://pastebin.com/GB4iiEwR
- http://www.exploit-db.com/exploits/26452
- http://www.exploit-db.com/exploits/27191
- http://www.novell.com/support/kb/doc.php?id=7012497
→ the Explorer · watch your stack · NVD