CVE-2013-3129

Description

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka TrueType Font Parsing Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
51.653

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows XP, Windows Server 2003 (64-bit), Windows Vista, and Windows Server 2008 (KB2833941)Windows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2833940) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2833940) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2844285) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2844285) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2832411) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2832411) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 Service Pack 1 on Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 (KB2840629) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 Service Pack 1 on Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 (KB2840629) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008 (KB2832407) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008 (KB2832407) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2835393) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2835393) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2840628) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2840628) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack 2 (32-bit) (KB2833949)Windows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2833947) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2833947) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2844287) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2844287) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2832412) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2832412) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2835622) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2835622) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2833957) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2833957) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2840642) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2840642) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2832414) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2832414) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2833946) x86 based systemsWindows
Security Update for Windows XP (KB2850851)Windows
Security Update for Windows Server 2003 (KB2850851)Windows
Security Update for Windows Vista (KB2850851)Windows
Security Update for Windows Server 2008 (KB2850851)Windows
Security Update for Windows 7 (KB2850851)Windows
Security Update for Windows XP x64 Edition (KB2850851)Windows
Security Update for Windows Server 2003 x64 Edition (KB2850851)Windows
Security Update for Windows Vista for x64-based Systems (KB2850851)Windows
Security Update for Windows Server 2008 x64 Edition (KB2850851)Windows
Security Update for Windows 7 for x64-based Systems (KB2850851)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2850851)Windows
Security Update for Windows 8 (KB2850851)Windows
Security Update for Windows 8 for x64-based Systems (KB2850851)Windows
Security Update for Windows Server 2012 (KB2850851)Windows
Security Update for Microsoft Office 2007 suites (KB2687309)Windows
Security Update for Microsoft Office 2010 (KB2687276) 32-Bit EditionWindows
Security Update for Windows XP (KB2834886)Windows
Security Update for Windows Server 2003 (KB2834886)Windows
Security Update for Windows Vista (KB2834886)Windows
Security Update for Windows Server 2008 (KB2834886)Windows
Security Update for Windows 7 (KB2834886)Windows
Security Update for Windows XP x64 Edition (KB2834886)Windows
Security Update for Windows Server 2003 x64 Edition (KB2834886)Windows
Security Update for Windows Vista for x64-based Systems (KB2834886)Windows
Security Update for Windows Server 2008 x64 Edition (KB2834886)Windows
Security Update for Windows 7 for x64-based Systems (KB2834886)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2834886)Windows
Security Update for Windows Vista (KB2835361)Windows
Security Update for Windows Server 2008 (KB2835361)Windows
Security Update for Windows 7 (KB2835361)Windows
Security Update for Windows Vista for x64-based Systems (KB2835361)Windows
Security Update for Windows Server 2008 x64 Edition (KB2835361)Windows
Security Update for Windows 7 for x64-based Systems (KB2835361)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2835361)Windows
Security Update for Windows 8 (KB2835361)Windows
Security Update for Windows 8 for x64-based Systems (KB2835361)Windows
Security Update for Windows Server 2012 (KB2835361)Windows
Security Update for Windows Vista (KB2835364)Windows
Security Update for Windows Server 2008 (KB2835364)Windows
Security Update for Windows 7 (KB2835364)Windows
Security Update for Windows Vista for x64-based Systems (KB2835364)Windows
Security Update for Microsoft Office 2010 (KB2687276) 64-Bit EditionWindows
Security Update for Windows 7 for x64-based Systems (KB2835364)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2835364)Windows
Security Update for Windows 8 (KB2835364)Windows
Security Update for Windows 8 for x64-based Systems (KB2835364)Windows
Security Update for Windows Server 2012 (KB2835364)Windows
Security Update for Microsoft Lync 2010 (32 -bit) (KB2843160)Windows
Security Update for Microsoft Lync 2010 (64 -bit) (KB2843160)Windows
Security Update for Microsoft Lync 2010 Attendee (Admin level install) (KB2843163)Windows
Security Update for Microsoft Lync 2013 (KB2817465) 32-Bit EditionWindows
Security Update for Microsoft Lync 2013 (KB2817465) 64-Bit EditionWindows
Visual Studio .NET 2003 Service Pack 1 GDIPLUS.DLL Security UpdateWindows
Security Update for Windows Server 2008 x64 Edition (KB2835364)Windows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2833946) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2840631)Windows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2840631) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2844286) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2844286) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2832418) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2832418) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2833959) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2833959) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2840633) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2840633) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2844289)Windows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2844289)Windows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2833958) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2833958) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2840632) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2840632) x64 bases systemsWindows
Security Update for Microsoft Silverlight (KB2847559) x64 bases systemsWindows
Security Update for Microsoft Silverlight (KB2847559)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13863Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2833940)
PATCH-13864Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2833940)
PATCH-13865Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2844285)
PATCH-13866Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2844285)
PATCH-13867Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2832411)
PATCH-13868Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2832411)
PATCH-13869Security Update for Microsoft .NET Framework 3.5 Service Pack 1 on Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 (KB2840629)
PATCH-13870Security Update for Microsoft .NET Framework 3.5 Service Pack 1 on Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 (KB2840629)
PATCH-13871Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008 (KB2832407)
PATCH-13872Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008 (KB2832407)
PATCH-13873Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2835393)
PATCH-13874Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2835393)
PATCH-13875Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2840628)
PATCH-13876Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2840628)
PATCH-13878Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2833947)
PATCH-13879Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2833947)
PATCH-13880Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2844287)
PATCH-13881Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2844287)
PATCH-13884Security Update for Microsoft .NET Framework 4.5 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2835622)
PATCH-13885Security Update for Microsoft .NET Framework 4.5 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2835622)
PATCH-13886Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2833957)
PATCH-13887Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2833957)
PATCH-13888Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2840642)
PATCH-13889Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2840642)
PATCH-13890Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2832414)
PATCH-13891Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2832414)
PATCH-13892Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2833946)
PATCH-13894Security Update for Windows Server 2003 (KB2850851)
PATCH-13895Security Update for Windows Vista (KB2850851)
PATCH-13896Security Update for Windows Server 2008 (KB2850851)
PATCH-13897Security Update for Windows 7 (KB2850851)
PATCH-13898Security Update for Windows XP x64 Edition (KB2850851)
PATCH-13899Security Update for Windows Server 2003 x64 Edition (KB2850851)
PATCH-13900Security Update for Windows Vista for x64-based Systems (KB2850851)
PATCH-13901Security Update for Windows Server 2008 x64 Edition (KB2850851)
PATCH-13902Security Update for Windows 7 for x64-based Systems (KB2850851)
PATCH-13903Security Update for Windows Server 2008 R2 x64 Edition (KB2850851)
PATCH-13904Security Update for Windows 8 (KB2850851)
PATCH-13905Security Update for Windows 8 for x64-based Systems (KB2850851)
PATCH-13906Security Update for Windows Server 2012 (KB2850851)
PATCH-13908Security Update for Microsoft Office 2007 suites (KB2687309)
PATCH-13909Security Update for Microsoft Office 2010 (KB2687276) 32-Bit Edition
PATCH-13911Security Update for Windows Server 2003 (KB2834886)
PATCH-13912Security Update for Windows Vista (KB2834886)
PATCH-13913Security Update for Windows Server 2008 (KB2834886)
PATCH-13914Security Update for Windows 7 (KB2834886)
PATCH-13915Security Update for Windows XP x64 Edition (KB2834886)
PATCH-13916Security Update for Windows Server 2003 x64 Edition (KB2834886)
PATCH-13917Security Update for Windows Vista for x64-based Systems (KB2834886)
PATCH-13918Security Update for Windows Server 2008 x64 Edition (KB2834886)
PATCH-13919Security Update for Windows 7 for x64-based Systems (KB2834886)
PATCH-13920Security Update for Windows Server 2008 R2 x64 Edition (KB2834886)
PATCH-13921Security Update for Windows Vista (KB2835361)
PATCH-13922Security Update for Windows Server 2008 (KB2835361)
PATCH-13923Security Update for Windows 7 (KB2835361)
PATCH-13924Security Update for Windows Vista for x64-based Systems (KB2835361)
PATCH-13925Security Update for Windows Server 2008 x64 Edition (KB2835361)
PATCH-13926Security Update for Windows 7 for x64-based Systems (KB2835361)
PATCH-13927Security Update for Windows Server 2008 R2 x64 Edition (KB2835361)
PATCH-13928Security Update for Windows 8 (KB2835361)
PATCH-13929Security Update for Windows 8 for x64-based Systems (KB2835361)
PATCH-13930Security Update for Windows Server 2012 (KB2835361)
PATCH-13931Security Update for Windows Vista (KB2835364)
PATCH-13932Security Update for Windows Server 2008 (KB2835364)
PATCH-13933Security Update for Windows 7 (KB2835364)
PATCH-13934Security Update for Windows Vista for x64-based Systems (KB2835364)
PATCH-13935Security Update for Microsoft Office 2010 (KB2687276) 64-Bit Edition
PATCH-13936Security Update for Windows 7 for x64-based Systems (KB2835364)
PATCH-13937Security Update for Windows Server 2008 R2 x64 Edition (KB2835364)
PATCH-13938Security Update for Windows 8 (KB2835364)
PATCH-13939Security Update for Windows 8 for x64-based Systems (KB2835364)
PATCH-13940Security Update for Windows Server 2012 (KB2835364)
PATCH-13944Security Update for Microsoft Lync 2013 (KB2817465) 32-Bit Edition
PATCH-13945Security Update for Microsoft Lync 2013 (KB2817465) 64-Bit Edition
PATCH-13946Visual Studio .NET 2003 Service Pack 1 GDIPLUS.DLL Security Update
PATCH-13947Security Update for Windows Server 2008 x64 Edition (KB2835364)
PATCH-14036Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2833946)
PATCH-14038Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2840631)
PATCH-14039Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2844286)
PATCH-14040Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2844286)
PATCH-14041Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2832418)
PATCH-14042Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2832418)
PATCH-14043Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2833959)
PATCH-14044Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2833959)
PATCH-14045Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2840633)
PATCH-14046Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2840633)
PATCH-14047Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2844289)
PATCH-14048Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2844289)
PATCH-14051Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2840632)
PATCH-14052Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2840632)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234