AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-3661

MEDIUM · CVSS 4.9 EPSS 3.85% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-05-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2013-3661
Severity
MEDIUM
CVSS
4.9
EPSS
3.85%
Microsoft Windows

Original NVD Description

The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.