CVE-2013-3128
published 2013-10-09CVE-2013-3128: The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…
PriorityP180critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
50.37%
98.8th percentile
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | windows_server_2008 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit loader allocates memory with PAGE_EXECUTE_READWRITE permissions; this memory protection flag combined with the Add.dll/AddByGod pattern can be used as a behavioral detection signal. ↗
- →The embedded exploit binary (inner payload) has a compilation timestamp of October 2014; forensic triage of loader samples should check for this embedded PE timestamp to confirm Jian/EpMe lineage. ↗
- →All malware samples using this packer variant are exclusively attributed to Chinese-affiliated attack groups; any sample matching the Add.dll/AddByGod packer pattern should be triaged under APT31 (Zirconium) attribution. ↗
- →The exploit targets a crafted OpenType Font (OTF) file to achieve remote code execution via kernel-mode driver parsing; hunt for anomalous OTF file delivery (email attachments, web downloads) on affected Windows/Server/.NET Framework versions. ↗
- ·The exploit uses a decryption password passed as a command-line argument; the specific password differs between samples (CVE-2017-0005 vs CVE-2019-0803) and is not disclosed in the source, limiting static signature coverage. ↗
- ·When ignoring random page allocation, both the Microsoft-documented sample and the researchers' sample use the same lower 3 nibbles of addresses; ASLR bypass behavior means address-based signatures must account for the randomized upper bits. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cp6p-w36w-x52m: The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
ghsa_unreviewed·2022-05-13
CVE-2013-3128 [HIGH] GHSA-cp6p-w36w-x52m: The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."
VulnCheck
Microsoft Windows OpenType Font Parsing Vulnerability
vulncheck·2013·CVSS 9.3
CVE-2013-3128 [CRITICAL] Microsoft Windows OpenType Font Parsing Vulnerability
Microsoft Windows OpenType Font Parsing Vulnerability
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://research.checkpoint.com/2021/the-story-of-jian/
No detection rules found.
Checkpoint
The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
blogs_checkpoint·2021-02-22
CVE-2017-0005 The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
Research by: Eyal Itkin and Itay Cohen
There is a theory which states that if anyone will ever manage to steal
Talos
Microsoft Update Tuesday October 2013: Another IE 0-day release
blogs_talos·2013-10-08·CVSS 9.3
CVE-2013-3893 [CRITICAL] Microsoft Update Tuesday October 2013: Another IE 0-day release
This month's Microsoft Tuesday Update brings us 8 bulletins for a total of 26 CVEs. Four of these bulletins are marked as critical, while the rest are marked as important.
First, let's take a look at the 4 critical bulletins:
The most important update this month is a cumulative update for IE (MS13-080), which fixes 10 CVE issues, 2 of which have already been exploited by attackers. The first 0-day that's being fixed was widely reported and exploited (CVE-2013-3893). The second one (CVE-2013-3897) was also exploited on the web, but in a more targeted manner. We have a blog post concerning this vulnerability here. Most of the issues fixed in this bulletin are the result of use-after-free vulnerabilities.
The second bulletin (MS13-081) covers Windows Kernel Mode Drivers. One particularly i
Talos
Microsoft Update Tuesday October 2013: Another IE 0-day release
blogs_talos·2013-10-08·CVSS 9.3
[CRITICAL] Microsoft Update Tuesday October 2013: Another IE 0-day release
## Microsoft Update Tuesday October 2013: Another IE 0-day release
This month's Microsoft Tuesday Update brings us 8 bulletins for a total of 26 CVEs. Four of these bulletins are marked as critical, while the rest are marked as important.
First, let's take a look at the 4 critical bulletins:
The most important update this month is a cumulative update for IE ( MS13-080 ), which fixes 10 CVE issues, 2 of which have already been exploited by attackers. The first 0-day that's being fixed was widely reported and exploited ( CVE-2013-3893 ). The second one ( CVE-2013-3897 ) was also exploited on the web, but in a more targeted manner. We have a blog post concerning this vulnerability here . Most of the issues fixed in this bulletin are the result of use-after-free vulnerabilities.
The second
Zscaler
Zscaler Protects against Memory Corruption in IE
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler Protects against Memory Corruption in IE
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.us-cert.gov/ncas/alerts/TA13-288Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-081https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-082https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18847http://www.us-cert.gov/ncas/alerts/TA13-288Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-081https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-082https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18847
2013-10-09
Published
Exploited in the wild