9.3
CVSSv2

CVE-2013-3129

Published: 10/07/2013 Updated: 07/12/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 prior to 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote malicious users to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net framework 4.0

microsoft silverlight 5.0.60818.0

microsoft visual studio .net 2003

microsoft lync 2010

microsoft office 2010

microsoft silverlight 5.1.10411.0

microsoft office 2007

microsoft lync 2013

microsoft silverlight 5.0.61118.0

microsoft silverlight 5.1.20125.0

microsoft silverlight 5.0.60401.0

microsoft .net framework 4.5

microsoft lync basic 2013

microsoft .net framework 3.5

microsoft .net framework 3.0

microsoft .net framework 3.5.1

microsoft office 2003

microsoft windows server 2008

microsoft windows rt -

microsoft windows xp -

microsoft windows 8 -

microsoft windows xp

microsoft windows 7

microsoft windows server 2003

microsoft windows vista

microsoft windows server 2012 -

Recent Articles

Windows kernel bug-squish, IE update star in July Patch Tuesday
The Register • John Leyden • 10 Jul 2013

Plus: Dodgy app unpatched for 180 days? We'll kick it out of Marketplace

Microsoft's Patch Tuesday for July landed overnight with a bumper crop of seven bulletins, six of which cover critical flaws that carry remote code execution risks. And the Windows 8 giant today revealed that one of these, CVE-2013-3163, is currently under active attack online. Every supported operating system, every version of MS Office, Lync, Silverlight, Visual Studio and .NET will need patching - creating plenty of work for sysadmins worldwide. The patch batch grapples with a total of 34 vul...

Microsoft Updates July 2013
Securelist • Kurt Baumgartner • 09 Jul 2013

As promised in Microsoft’s July Advance Notification, Microsoft ships seven security bulletins this month (MS13-052 – MS13-058). At least 34 CVE are being patched. Six of the Security Bulletins are rated “critical” due to remote code execution issues. The vulnerabilities being fixed this month enable RCE across all versions of Windows operating systems, but most of these serious flaws have all been privately reported and there is no indication that they are publicly known or exploited ye...