You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ms13-102
About this tag
MS13-102 is a security bulletin from Microsoft addressing a vulnerability in the LRPC (Local Remote Procedure Call) client that could allow elevation of privilege. The update, released on December 10, 2013, resolves a privately reported issue where an attacker with valid logon credentials could send a specially crafted LPC port message to any LPC consumer or server. Successful exploitation could enable the attacker to install programs, view or change data, or create new accounts with full administrator rights. The vulnerability requires local access to exploit. This bulletin is part of Microsoft's ongoing efforts to patch critical security flaws in Windows systems.
Severity Rating: Important
Revision Note: V1.0 (December 10, 2013): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Windows. The vulnerability could allow elevation of privilege if an attacker sends a specially crafted LPC port message to any LPC...