First published: Wed Jul 10 2013(Updated: )
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework | =3.0-sp2 | |
Microsoft .NET Framework | =3.5 | |
Microsoft .NET Framework | =3.5.1 | |
Microsoft .NET Framework | =4.0 | |
Microsoft .NET Framework | =4.5 | |
Microsoft Lync | =2010 | |
Microsoft Lync | =2010 | |
Microsoft Lync | =2010 | |
Microsoft Lync | =2013 | |
Microsoft Lync | =2013 | |
Microsoft Lync Basic | =2013 | |
Microsoft Lync Basic | =2013 | |
Microsoft Office | =2003-sp3 | |
Microsoft Office | =2007-sp3 | |
Microsoft Office | =2010-sp1 | |
Microsoft Office | =2010-sp1 | |
Microsoft Silverlight | =5.0.60401.0 | |
Microsoft Silverlight | =5.0.60818.0 | |
Microsoft Silverlight | =5.0.60818.0-rc | |
Microsoft Silverlight | =5.0.61118.0 | |
Microsoft Silverlight | =5.1.10411.0 | |
Microsoft Silverlight | =5.1.20125.0 | |
Microsoft Visual Studio .NET | =2003-sp1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8 | ||
Microsoft Windows 8 | ||
Microsoft Windows Rt | ||
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2012 | ||
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.