CVE-2013-1286 is a memory handling vulnerability in the USB kernel-mode drivers across various Microsoft Windows operating systems, including XP, Vista, Windows 7, 8, and Server versions. This flaw allows a physically proximate attacker to execute arbitrary code by connecting a specially crafted USB device. With a CVSS score of 7.2, it represents a high severity local attack with full confidentiality, integrity, and availability impact. While the vulnerability is not listed in CISA's KEV catalog and lacks public exploit intelligence or significant community discussion, its nature as a local privilege escalation via physical access makes it a notable risk for targeted attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.