peter bassill · operator
$ cve CVE-2013-3956 JSON

CVE-2013-3956 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 7.8% (pctl 94)

Patch early

A public exploit exists.

Description

The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted 0x143B6B IOCTL call.

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS7.8% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2013-07-31
Last modified2026-06-16

Affected (7)

VendorProduct
microsoftwindows 2003 server
microsoftwindows 7
microsoftwindows 8
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp
novellclient

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD