Lucene search

K
cveMicrosoftCVE-2013-3128
HistoryOct 09, 2013 - 2:53 p.m.

CVE-2013-3128

2013-10-0914:53:24
microsoft
web.nvd.nist.gov
135
cve-2013-3128
remote code execution
opentype font parsing
nvd
microsoft
windows xp
windows server
windows vista
windows 7
windows 8
windows rt
.net framework

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.755

Percentile

98.2%

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka “OpenType Font Parsing Vulnerability.”

Affected configurations

Nvd
Node
microsoftwindows_7Match-sp1x64
OR
microsoftwindows_7Match-sp1x86
OR
microsoftwindows_8Match-x64
OR
microsoftwindows_8Match-x86
OR
microsoftwindows_rtMatch-
OR
microsoftwindows_server_2003Match-sp2
OR
microsoftwindows_server_2003Match-sp2itanium
OR
microsoftwindows_server_2003Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2itanium
OR
microsoftwindows_server_2008Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_server_2008Matchr2sp1itanium
OR
microsoftwindows_server_2008Matchr2sp1x64
OR
microsoftwindows_server_2012Match-
OR
microsoftwindows_vistaMatch-sp2
OR
microsoftwindows_vistaMatch-sp2x64
OR
microsoftwindows_xpMatch-sp2professionalx64
OR
microsoftwindows_xpMatch-sp3
Node
microsoft.net_frameworkMatch3.0sp2
AND
microsoftwindows_server_2003Match-sp2
OR
microsoftwindows_server_2003Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_vistaMatch-sp2
OR
microsoftwindows_vistaMatch-sp2x64
OR
microsoftwindows_xpMatch-sp2professionalx64
OR
microsoftwindows_xpMatch-sp3
Node
microsoft.net_frameworkMatch3.5-
AND
microsoftwindows_8Match-x64
OR
microsoftwindows_8Match-x86
OR
microsoftwindows_server_2012Match-
Node
microsoft.net_frameworkMatch3.5.1
AND
microsoftwindows_7Match-sp1x86
OR
microsoftwindows_server_2008Matchr2sp1x64
Node
microsoft.net_frameworkMatch4.0-
AND
microsoftwindows_server_2003Match-sp2
OR
microsoftwindows_server_2003Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_vistaMatch-sp2
OR
microsoftwindows_vistaMatch-sp2x64
OR
microsoftwindows_xpMatch-sp2professionalx64
OR
microsoftwindows_xpMatch-sp3
Node
microsoft.net_frameworkMatch4.5
AND
microsoftwindows_server_2008Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_vistaMatch-sp2
OR
microsoftwindows_vistaMatch-sp2x64
VendorProductVersionCPE
microsoftwindows_7-cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:*
microsoftwindows_7-cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x86:*
microsoftwindows_8-cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:x64:*
microsoftwindows_8-cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:x86:*
microsoftwindows_rt-cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:itanium:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:x64:*
microsoftwindows_server_2008-cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:itanium:*
microsoftwindows_server_2008-cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*
Rows per page:
1-10 of 231

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.755

Percentile

98.2%