SHARE
Facebook X Pinterest WhatsApp

Microsoft Plugs Evil Maid USB Flaws

Mar 14, 2013

The MS13-027 bulletin describes one of the most interesting sets of flaws that Microsoft is fixing this month. The bulletin titled “Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege” encompasses three separate vulnerabilities (CVE-2013-1285, CVE-2013-1286 and CVE-2013-1287), all of which are labeled as “Windows USB Descriptor Vulnerability.”

“An elevation of privilege vulnerability exists when Windows USB drivers improperly handle objects in memory,” Microsoft warns. “An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.”

Qualys CTO , Wolfgang Kandek noted that the attack vector used in the USB vulnerability was described as far back as 2009 as the “evil maid” attack.

“The attack vector is broad, encompassing anybody who has access to your unattended computer, be it the janitor at your workplace, the staff at the hotel where you are staying, or anywhere somebody with physical access can insert a USB drive into your computer,” Kandek said.

Read the full story at eSecurity Planet:
Microsoft Patch Tues Misses Pwn2own Flaws

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals Follow him on Twitter @TechJournalist.

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.