CVE-2013-3129
published 2013-07-10CVE-2013-3129: Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and…
PriorityP354high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
32.38%
98.1th percentile
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | lync_basic | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | visual_studio_net | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs: 27126-27139, 27147-27154, 27156-27157
- →CVE-2013-3129 is triggered by a maliciously crafted TrueType Font (TTF) file; detect delivery via documents or web content embedding TTF files targeting Windows GDI+, DirectWrite, win32k.sys, .NET Framework, and Silverlight. ↗
- →The vulnerability can be exploited by having a user visit a web page containing malicious TrueType content — monitor HTTP responses delivering TTF/font data to unpatched Windows systems. ↗
- →CVE-2013-3129 is addressed across three separate Microsoft bulletins (MS13-052, MS13-053, MS13-054); ensure all three patches are applied — missing any one leaves the attack surface open via .NET/Silverlight, win32k.sys kernel, or GDI+ respectively. ↗
- ·CVE-2013-3129 spans three separate bulletins (MS13-052, MS13-053, MS13-054) covering different components (.NET/Silverlight, Windows Kernel/win32k.sys, GDI+); detection and patching must address all three attack surfaces independently. ↗
- ·The Talos Snort SID ranges (27126-27139, 27147-27154, 27156-27157) cover multiple CVEs from the July 2013 Update Tuesday batch, not exclusively CVE-2013-3129; validate individual SID coverage before relying on them for this specific CVE. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Update Tuesday: July 2013: an issue of TrueType fonts
blogs_talos·2013-07-10·CVSS 7.8
[HIGH] Microsoft Update Tuesday: July 2013: an issue of TrueType fonts
This month's Update Tuesday looks pretty interesting. As usual, there's quite a few CVEs covered and most of them are once again in IE: there's a total of 7 bulletins, covering 34 CVE issues. However, one CVE is shared between 3 bulletins.
MS13-052 covers the .NET framework and Silverlight. There's a total of 7 CVEs fixed by the update associated with this bulletin. The bulletin is marked critical and could result in remote code execution or escalation of privileges if one of these vulnerabilities is exploited.
There's a total of 8 CVE isusues this month that pertain to the Windows Kernel, described in MS13-053. This bulletin is considered critical and can result in remote code execution, specifically due to vulnerability related to TrueType fonts, which we discuss as part of MS13-054. O
Talos
Microsoft Update Tuesday: July 2013: an issue of TrueType fonts
blogs_talos·2013-07-10·CVSS 7.8
[HIGH] Microsoft Update Tuesday: July 2013: an issue of TrueType fonts
## Microsoft Update Tuesday: July 2013: an issue of TrueType fonts
This month's Update Tuesday looks pretty interesting. As usual, there's quite a few CVEs covered and most of them are once again in IE: there's a total of 7 bulletins, covering 34 CVE issues. However, one CVE is shared between 3 bulletins.
MS13-052 covers the .NET framework and Silverlight. There's a total of 7 CVEs fixed by the update associated with this bulletin. The bulletin is marked critical and could result in remote code execution or escalation of privileges if one of these vulnerabilities is exploited.
There's a total of 8 CVE isusues this month that pertain to the Windows Kernel, described in MS13-053 . This bulletin is considered critical and can result in remote code execution, specifically due to vulnerabili
Krebs
Adobe, Microsoft Release Critical Updates
blogs_krebs·2013-07-09·CVSS 7.8
[HIGH] Adobe, Microsoft Release Critical Updates
Patch Tuesday is upon us once again. Adobe today pushed out security fixes for its Flash and Shockwave media players. Separately, Microsoft released seven patch bundles addressing at least 34 vulnerabilities in Microsoft Windows and other software. At least one of the Windows flaws is already being exploited in active attacks.
Six of the seven Microsoft patches released today earned the company’s most dire “critical” rating, meaning the patches plug security holes that could be exploited by malware or miscreants with no help from PC users, save for visiting a hacked site or opening a specially crafted document.
Microsoft and security experts are calling special attention to MS13-053, which fixes at least eight flaws in Windows’ implementation of TrueType font files. These critical TrueTy
Krebs
Adobe, Microsoft Release Critical Updates – Krebs on Security
blogs_krebs·2013-07-01·CVSS 7.8
[HIGH] Adobe, Microsoft Release Critical Updates – Krebs on Security
Patch Tuesday is upon us once again. Adobe today pushed out security fixes for its Flash and Shockwave media players. Separately, Microsoft released seven patch bundles addressing at least 34 vulnerabilities in Microsoft Windows and other software. At least one of the Windows flaws is already being exploited in active attacks.
Six of the seven Microsoft patches released today earned the company’s most dire “critical” rating, meaning the patches plug security holes that could be exploited by malware or miscreants with no help from PC users, save for visiting a hacked site or opening a specially crafted document.
Microsoft and security experts are calling special attention to MS13-053 , which fixes at least eight flaws in Windows’ implementation of TrueType font files . These critical True
http://www.us-cert.gov/ncas/alerts/TA13-190Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-052https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-053https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-054https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17323https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17341http://www.us-cert.gov/ncas/alerts/TA13-190Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-052https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-053https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-054https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17323https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17341
2013-07-10
Published