CVE-2013-3697

Novell Client - Local Privilege Escalation via Crafted 0x1439EB IOCTL Call

Title source: llm
STIX 2.1

Description

Integer overflow in the NWFS.SYS kernel driver 4.91.5.8 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003 and the NCPL.SYS kernel driver in Novell Client 2 SP2 on Windows Vista and Windows Server 2008 and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 might allow local users to gain privileges via a crafted 0x1439EB IOCTL call.

References (2)

Core 2
Core References
Exploit x_refsource_misc
http://pastebin.com/RcS2Bucg
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7012497

Scores

EPSS 0.0002
EPSS Percentile 6.5%

Details

CWE
CWE-189
Status published
Products (2)
novell/client 4.91 sp5
novell/client 2.0 sp2 (2 CPE variants)
Published Jul 31, 2013
Tracked Since Feb 18, 2026