CVE-2013-3129

CWE-94Code Injection4 documents4 sources
Severity
7.8HIGH
EPSS
51.7%
top 2.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 13

Description

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attac

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDmicrosoft/lync2010, 2013+1
NVDmicrosoft/office2003, 2007, 2010+2
NVDmicrosoft/silverlight5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-rgv9-4g5g-3mp2: Microsoft2022-05-13
CVEList
CVE-2013-3129: Microsoft2013-07-10