CVE-2013-2556: Microsoft Windows 7
High severity, CVSS 7.5. EPSS: 7.6% chance of exploitation in the next 30 days.
Unspecified vulnerability in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 through SP1 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "ASLR Security Feature Bypass Vulnerability."
Affected products
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows Server 2008: any version
- Microsoft Windows Vista: any version
Published 2013-03-11. Last modified 2026-06-16.