Oval Definition:oval:org.mitre.oval:def:17341
Revision Date:2015-02-23Version:82
Title:TrueType Font Parsing Vulnerability - CVE-2013-3129 (MS13-052, MS13-053, MS13-054)
Description:Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-3129
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.0
Microsoft .NET Framework 4.5
Microsoft Lync 2010
Microsoft Lync 2010 Attendee
Microsoft Lync Basic 2013
Microsoft Office 2003
Microsoft Office 2007
Microsoft Office 2010
Microsoft Silverlight 5
Microsoft Visual Studio .NET 2003
Definition Synopsis
  • XP x86
  • Microsoft Windows XP (32-bit) is installed
  • AND Check if the version of Win32k.sys is less than 5.1.2600.6404
  • OR XP/2K3 and vulnerable file version
  • XP/2K3
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Check if the version of Win32k.sys is less than 5.2.3790.5174
  • OR Vista/2K8 and vulnerable file version
  • Vista/2K8
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Check for vulnerable version
  • Check if the version of Win32k.sys is less than 6.0.6002.18861
  • OR Check for LDR
  • Check if the version of Win32k.sys is less than 6.0.6002.23132
  • AND Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000
  • OR 7/2K8 R2 and vulnerable file version
  • 7/2K8 R2
  • Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • AND Check for vulnerable version
  • Check if the version of Win32k.sys is less than 6.1.7601.18176
  • OR Check for LDR
  • Check if the version of Win32k.sys is less than 6.1.7601.22348
  • AND Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000
  • OR 8/2k12 and vulnerable file version
  • 8/2k12
  • Microsoft Windows Server 2012 (64-bit) is installed
  • OR Microsoft Windows 8 (x64) is installed
  • OR Microsoft Windows 8 (x86) is installed
  • AND Check for vulnerable version
  • Check if the version of Win32k.sys is less than 6.2.9200.16627
  • OR Check for LDR
  • Check if the version of Win32k.sys is less than 6.2.9200.20732
  • AND Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000
  • OR .net 3.0 sp2/win xp/server 2003/versions
  • either os
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND GDR/LDR
  • Check if the version of xpsviewer.exe is less than 3.0.6920.4050
  • OR ldr range
  • Check if the version of xpsviewer.exe is greater than or equal to 3.0.6920.7000
  • AND Check if the version of xpsviewer.exe is less than 3.0.6920.7045
  • AND Microsoft .NET Framework 3.0 SP2 is installed
  • OR .net 3.0 sp2/vista/server 2008/versions
  • either os
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • AND GDR/LDR
  • Check if the version of xpsviewer.exe is less than 3.0.6920.4216
  • OR ldr range
  • Check if the version of xpsviewer.exe is greater than or equal to 3.0.6920.7000
  • AND Check if the version of xpsviewer.exe is less than 3.0.6920.7036
  • AND Microsoft .NET Framework 3.0 SP2 is installed
  • OR .net 3.5/win8/server 2012/versions
  • either os
  • Microsoft Windows 8 (x64) is installed
  • OR Microsoft Windows Server 2012 (64-bit) is installed
  • OR Microsoft Windows 8 (x86) is installed
  • AND Microsoft .NET Framework 3.5 SP1 is installed
  • AND GDR/LDR
  • Check if the version of presentationcore.dll is less than 3.0.6920.6402
  • OR ldr range
  • Check if the version of presentationcore.dll is less than 3.0.6920.7036
  • AND Check if the version of presentationcore.dll is greater than or eqaul to 3.0.6920.7000
  • OR .net 3.5.1/win 7/server 2008 R2/versions
  • either os
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • AND Microsoft .NET Framework 3.5 SP1 is installed
  • AND either file versions
  • Check if the version of system.printing.dll is less than 3.0.6920.5453
  • OR ldr range
  • Check if the version of system.printing.dll is less than 3.0.6920.7036
  • AND Check if the version of system.printing.dll is greater than or equal to 3.0.6920.7000
  • OR .net 4.0/win xp.server 2003/vista/server 2008/versions
  • either os
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • AND Microsoft .NET Framework 4.0 is installed
  • AND GDR/LDR
  • Check if the version of presentationcore.dll is less than 4.0.30319.1005
  • OR ldr range
  • Check if the version of presentationcore.dll is less than 4.0.30319.2009
  • AND Check if the version of presentationcore.dll is greater than or equal to 4.0.30319.2000
  • OR .net 4.5/vista/server 2008/versions
  • either os
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • AND GDR/LDR
  • Check if the version of wpftxt_v0400.dll is less than 4.0.30319.18049
  • OR ldr range
  • Check if the version of wpftxt_v0400.dll is less than 4.0.30319.19077
  • AND Check if the version of wpftxt_v0400.dll is greater than or equal to 4.0.30319.19000
  • AND Microsoft .NET Framework 4.5 is installed
  • OR silverlight/version
  • Microsoft Silverlight 5 is installed
  • AND Check if the version of Silverlight is less than 5.1.20513
  • OR For vulnerable OS and vulnerable file version
  • For OS
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • OR Microsoft Windows XP x64 is installed
  • AND Check if the version of Gdiplus.dll is less than 5.2.6002.23084
  • OR For vulnerable OS and vulnerable file version
  • For OS
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Either file version
  • Check if the version of Gdiplus.dll is less than 6.0.6002.18813
  • OR For LDR
  • Check if the version of Gdiplus.dll is greater than or equal to 6.0.6002.23000
  • AND Check if the version of Gdiplus.dll is less than 6.0.6002.23084
  • OR Check if the version of Dwrite.dll is less than 7.0.6002.18827
  • OR For LDR
  • Check if the version of Dwrite.dll is greater than or equal to 7.0.6002.23000
  • AND Check if the version of Dwrite.dll is less than 7.0.6002.23097
  • OR Check if the version of Jntfiltr.dll is less than 6.0.6002.18817
  • OR For LDR
  • Check if the version of Jntfiltr.dll is less than 6.0.6002.23094
  • AND the version of Jntfiltr.dll is greater than or equal to 6.0.6002.23000
  • OR For vulnerable OS and vulnerable file version
  • For OS
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND For GDR/LDR
  • Check if the version of Gdiplus.dll is less than 6.1.7601.18120
  • OR For LDR
  • Check if the version of Gdiplus.dll is greater than or equal to 6.1.7601.22000
  • AND Check if the version of Gdiplus.dll is less than 6.1.7601.22290
  • OR For vulnerable OS and vulnerable file version
  • For OS
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND File section
  • For GDR/LDR
  • For GDR
  • Check if the version of Dwrite.dll is less than 6.2.9200.16571
  • AND Check if the version of Dwrite.dll is greater than or equal 6.2.9200.16000
  • OR For LDR
  • Check if the version of Dwrite.dll is greater than or equal 6.2.9200.20000
  • AND Check if the version of Dwrite.dll is less than 6.2.9200.20675
  • OR For GDR/LDR
  • Check if the version of Dwrite.dll is less than 6.1.7601.18126
  • OR For LDR
  • Check if the version of Dwrite.dll is greater than or equal to 6.1.7601.22000
  • AND Check if the version of Dwrite.dll is less than 6.1.7601.22296
  • OR For vulnerable OS and vulnerable file version
  • Microsoft Windows Server 2008 R2 x64 Edition is installed
  • AND For GDR/LDR
  • Check if the version of Jntfiltr.dll is less than 6.1.7601.18126
  • OR For LDR
  • Check if the version of Jntfiltr.dll is greater than or equal to 6.1.7601.22000
  • AND Check if the version of Jntfiltr.dll is less than 6.1.7601.22296
  • OR For vulnerable OS and vulnerable file version
  • Microsoft Windows 8 (x86) is installed
  • AND Either file version
  • Check if the version of Dwrite.dll is less than 6.2.9200.16581
  • OR For LDR
  • Check if the version of Dwrite.dll is greater than or equal 6.2.9200.20000
  • AND Check if the version of Dwrite.dll is less than 6.2.9200.20685
  • OR Check if the version of Jntfiltr.dll is less than 6.2.9200.16581
  • OR For LDR
  • Check if the version of Jntfiltr.dll is greater than or equal 6.2.9200.20000
  • AND Check if the version of Jntfiltr.dll is less than 6.2.9200.20685
  • OR For vulnerable OS and vulnerable file version
  • Win 8/2012
  • Microsoft Windows 8 (x64) is installed
  • OR Microsoft Windows Server 2012 (64-bit) is installed
  • AND Either file version
  • Check if the version of Dwrite.dll is less than 6.2.9200.16579
  • OR For LDR
  • Check if the version of Dwrite.dll is greater than or equal 6.2.9200.20000
  • AND Check if the version of Dwrite.dll is less than 6.2.9200.20682
  • OR Check if the version of Jntfiltr.dll is less than 6.2.9200.16579
  • OR For LDR
  • Check if the version of Jntfiltr.dll is greater than or equal 6.2.9200.20000
  • AND Check if the version of Jntfiltr.dll is less than 6.2.9200.20682
  • OR For Office 2003 SP3 and vulnerable file version
  • Microsoft Office 2003 SP3 is installed
  • AND Check if the version of GDIPLUS.DLL is less than 11.0.8404
  • OR For Office 2007 SP3 and vulnerable file version
  • Microsoft Office 2007 SP3 is installed
  • AND Check if the version of Ogl.dll is less than 12.0.6679.5000
  • OR For Office 2010 SP1 and vulnerable file version
  • Microsoft Office 2010 SP1 is installed
  • AND Check if the version of Ogl.dll is less than 14.0.7102.5000
  • OR For Microsoft Visual Studio .NET 2003 SP1 and vulnerable file version
  • Microsoft Visual Studio .NET 2003 SP1 is installed
  • AND Check if the version of Mso.dll is less than 10.0.6885.0
  • OR For vulnerable Microsoft Lync 2010
  • Microsoft Lync 2010 is installed
  • AND Check if the version of Ogl.dll (Lync 2010) is less than 4.0.7577.4392
  • OR For vulnerable Microsoft Lync 2010 attendee (admin)
  • Microsoft Lync 2010 Attendee (admin level install) is installed
  • AND Check if the version of ogl.dll (Lync 2010 Attendee for admin) is less than 4.0.7577.4392
  • OR For vulnerable Microsoft Lync 2010 attendee (user)
  • Microsoft Lync 2010 Attendee (user level install) is installed
  • AND Check if the version of ogl.dll (Lync 2010 Attendee for user) is less than 4.0.7577.4392
  • OR For vulnerable Microsoft Lync Basic 2013
  • Microsoft Lync Basic 2013 is installed
  • AND Check if the version of lynchtmlconv.exe is less than 15.0.4517.1003
  • BACK