HTTP: Adobe Acrobat Reader CVE-2013-5065 Malicious Dropper
This signature detects the pdf dropper that is being used in-the-wild to exploit a known privilege escalation vulnerability against Windows XP and Windows Server 2003. Successful exploitation could lead to arbitrary code execution in Kernel mode.
Extended Description
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
Affected Products
Microsoft windows_2003_server
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
7.2