First published: Wed Aug 14 2013(Updated: )
usp10.dll in the Unicode Scripts Processor in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3181 is classified as critical due to its potential to allow remote code execution.
To fix CVE-2013-3181, install the security update provided by Microsoft for Windows XP and Windows Server 2003.
CVE-2013-3181 affects users running Windows XP SP2, Windows XP SP3, and Windows Server 2003 SP2.
CVE-2013-3181 is a memory corruption vulnerability associated with the OpenType font parsing in Windows.
Yes, attackers can exploit CVE-2013-3181 by using crafted OpenType fonts to execute arbitrary code on affected systems.