CVE-2013-3129
Summary
| CVE | CVE-2013-3129 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-10 03:46:00 UTC |
| Updated | 2023-12-07 18:38:00 UTC |
| Description | Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability." |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | .net Framework | 3.0 | sp2 | All | All |
| Application | Microsoft | .net Framework | 3.5 | All | All | All |
| Application | Microsoft | .net Framework | 3.5.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.0 | All | All | All |
| Application | Microsoft | .net Framework | 4.5 | All | All | All |
| Application | Microsoft | .net Framework | 3.0 | sp2 | All | All |
| Application | Microsoft | .net Framework | 3.5 | All | All | All |
| Application | Microsoft | .net Framework | 3.5.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.0 | All | All | All |
| Application | Microsoft | .net Framework | 4.5 | All | All | All |
| Application | Microsoft | Lync | 2010 | All | attendee | All |
| Application | Microsoft | Lync | 2010 | All | x64 | All |
| Application | Microsoft | Lync | 2010 | All | x86 | All |
| Application | Microsoft | Lync | 2013 | - | x64 | All |
| Application | Microsoft | Lync | 2013 | - | x86 | All |
| Application | Microsoft | Lync | 2010 | All | attendee | All |
| Application | Microsoft | Lync | 2010 | All | x64 | All |
| Application | Microsoft | Lync | 2010 | All | x86 | All |
| Application | Microsoft | Lync | 2013 | - | x64 | All |
| Application | Microsoft | Lync | 2013 | - | x86 | All |
| Application | Microsoft | Lync Basic | 2013 | - | x64 | All |
| Application | Microsoft | Lync Basic | 2013 | - | x86 | All |
| Application | Microsoft | Lync Basic | 2013 | - | x64 | All |
| Application | Microsoft | Lync Basic | 2013 | - | x86 | All |
| Application | Microsoft | Office | 2003 | sp3 | All | All |
| Application | Microsoft | Office | 2007 | sp3 | All | All |
| Application | Microsoft | Office | 2010 | sp1 | x64 | All |
| Application | Microsoft | Office | 2010 | sp1 | x86 | All |
| Application | Microsoft | Office | 2003 | sp3 | All | All |
| Application | Microsoft | Office | 2007 | sp3 | All | All |
| Application | Microsoft | Office | 2010 | sp1 | x64 | All |
| Application | Microsoft | Office | 2010 | sp1 | x86 | All |
| Application | Microsoft | Silverlight | 5.0.60401.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.0.60818.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.0.60818.0 | rc | All | All |
| Application | Microsoft | Silverlight | 5.0.61118.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.1.10411.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.1.20125.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.0.60401.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.0.60818.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.0.60818.0 | rc | All | All |
| Application | Microsoft | Silverlight | 5.0.61118.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.1.10411.0 | All | All | All |
| Application | Microsoft | Silverlight | 5.1.20125.0 | All | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | sp1 | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | sp1 | All | All |
| Operating System | Microsoft | Windows 7 | All | sp1 | x64 | All |
| Operating System | Microsoft | Windows 7 | All | sp1 | x86 | All |
| Operating System | Microsoft | Windows 7 | All | sp1 | x64 | All |
| Operating System | Microsoft | Windows 7 | All | sp1 | x86 | All |
| Operating System | Microsoft | Windows 8 | - | - | x64 | All |
| Operating System | Microsoft | Windows 8 | - | - | x86 | All |
| Operating System | Microsoft | Windows 8 | - | - | x64 | All |
| Operating System | Microsoft | Windows 8 | - | - | x86 | All |
| Operating System | Microsoft | Windows Rt | - | All | All | All |
| Operating System | Microsoft | Windows Rt | - | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | All | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | All | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x86 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x86 | All |
| Operating System | Microsoft | Windows Server 2012 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2012 | - | All | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Xp | All | sp3 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | x64 | All |
| Operating System | Microsoft | Windows Xp | All | sp3 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | x64 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Updates for Multiple Vulnerabilities | US-CERT | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Microsoft Security Bulletin MS13-052 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft Security Bulletin MS13-053 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Microsoft Security Bulletin MS13-054 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.