Vulnerability in Windows Essentials could allow information disclosure - MS13-045ID: oval:org.secpod.oval:def:10965 | Date: (C)2013-05-16 (M)2021-09-11 |
Class: PATCH | Family: windows |
The host is missing an important security update according to Microsoft bulletin, MS13-045. The update is required to fix information disclosure vulnerability. A flaw is present in the application, which fails to properly handle URL parameters. Successful exploitation allows attackers to override Windows Writer proxy settings and overwrite files accessible to the user on the target system.
Platform: |
Microsoft Windows 7 |
Microsoft Windows 8 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Product: |
Microsoft Windows Essentials 2012 |