MEDIUM · 4.7

CVE-2013-3903

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot)...

Vulnerability Description

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."

CVSS Score

4.7

MEDIUM

AV:L/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftWindows 8-
MicrosoftWindows Rt-
MicrosoftWindows Rt 8.1-
MicrosoftWindows Server 2012-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3903?

CVE-2013-3903 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot)...

How severe is CVE-2013-3903?

CVE-2013-3903 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3903?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 8, Microsoft Windows Rt, Microsoft Windows Rt 8.1, Microsoft Windows Server 2012.