Lucene search

K
cve[email protected]CVE-2013-3903
HistoryDec 11, 2013 - 12:55 a.m.

CVE-2013-3903

2013-12-1100:55:03
CWE-20
web.nvd.nist.gov
24
cve-2013-3903
array index error
win32k.sys
microsoft windows
denial of service
truetype font parsing vulnerability
nvd

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.4%

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka “TrueType Font Parsing Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_8Match--x64
OR
microsoftwindows_8Match--x86
OR
microsoftwindows_rtMatch-
OR
microsoftwindows_rt_8.1Match-
OR
microsoftwindows_server_2012Match-
OR
microsoftwindows_server_2012Matchr2datacenter
OR
microsoftwindows_server_2012Matchr2essentials
OR
microsoftwindows_server_2012Matchr2standard

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.4%