Vulnerability record · CVE-2013-3128 · published 9 October 2013
CVE-2013-3128: Microsoft Windows and .NET OpenType font parsing remote code execution
Microsoft · Windows 7
Kernel-mode drivers in Windows and the .NET Framework fail to properly handle crafted OpenType (OTF) font files, allowing memory corruption that can be turned into code execution. Because font parsing is reachable from ordinary document and web content, the flaw matters broadly across nearly all supported Windows versions of that era.
Description
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete confidentiality, integrity, and availability impact across a very wide install base, though exploitation requires a crafted font and medium attack complexity.
What it is
Kernel-mode drivers in Windows and the .NET Framework fail to properly handle crafted OpenType (OTF) font files, allowing memory corruption that can be turned into code execution. Because font parsing is reachable from ordinary document and web content, the flaw matters broadly across nearly all supported Windows versions of that era.
Impact
An attacker who gets a crafted OTF font parsed can execute arbitrary code in kernel mode, gaining full control of the affected system. This includes the ability to install programs, change data, and create accounts with full rights.
Attack surface
Reached remotely over the network (AV:N) by delivering a malicious OTF file, typically through a web page or document that triggers font parsing. No authentication is required (Au:N), but the CVSS vector indicates medium attack complexity (AC:M), implying some condition such as user interaction or a specific rendering path is needed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.504, ~98.9th percentile), and references are limited to vendor patches and government advisories, with no public exploit tag in the record.
What to do
- Apply the Microsoft patches referenced in MS13-081 and MS13-082 for all affected Windows and .NET Framework versions.
- Prioritize Windows XP, Server 2003, and other unsupported or end-of-life systems for upgrade or isolation, since they cannot receive current fixes.
- Restrict or block untrusted OTF font files at email and web gateways where feasible.
- Harden browser and document-viewer settings to limit automatic font loading from untrusted sources.
Detection
- Monitor for unexpected kernel-mode crashes or memory corruption events tied to font rendering (win32k/GDI components).
- Hunt for OTF files written to or loaded from unusual user directories or temporary paths.
- Review process creation and child-process behavior from browser, Office, or font-rendering processes for anomalies.
- Use the CISE OVAL definition to scan endpoints for missing MS13-081/MS13-082 patches.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.us-cert.gov/ncas/alerts/TA13-288A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-081 | PatchVendor Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-082 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18847 | Third Party Advisory |
| http://www.us-cert.gov/ncas/alerts/TA13-288A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-081 | PatchVendor Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-082 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18847 | Third Party Advisory |
Track CVE-2013-3128 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.