• caglararli@hotmail.com
  • 05386281520

MS13-027: Addressing an issue in the USB driver requiring physical access

Çağlar Arlı      -    14 Views

MS13-027: Addressing an issue in the USB driver requiring physical access

Today we are addressing a vulnerability in the way that the Windows USB drivers handle USB descriptors when enumerating devices. (KB 2807986). This update represents an expansion of our risk assessment methodology to recognize vulnerabilities that may require physical access, but do not require a valid logon session. Windows typically discovers USB devices when they are inserted or when they change power sources (if they switch from plugged-in power to being powered off of the USB connection itself).