CVE-2013-2556: Microsoft Windows 7

High severity, CVSS 7.5. EPSS: 7.6% chance of exploitation in the next 30 days.

Unspecified vulnerability in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 through SP1 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "ASLR Security Feature Bypass Vulnerability."

Affected products

Published 2013-03-11. Last modified 2026-06-16.