Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-5058. PoCs published by Core Security.
AI-analyzed exploit summary The exploit triggers a divide error in the Windows kernel by calling 'NtGdiGetTextExtent' with crafted arguments, causing an integer overflow in 'RFONTOBJ::bTextExtent' in 'win32k.sys'. This results in a denial of service (blue screen) on Windows XP and Windows 7.
Description
Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k Integer Overflow Vulnerability."
Exploits (1)
The exploit triggers a divide error in the Windows kernel by calling 'NtGdiGetTextExtent' with crafted arguments, causing an integer overflow in 'RFONTOBJ::bTextExtent' in 'win32k.sys'. This results in a denial of service (blue screen) on Windows XP and Windows 7.