CVE-2013-3129

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003 SP3, 2007 SP3, and 2010 SP1; GDI+ in Visual Studio .NET 2003 SP1; and GDI+ in Lync 2010, 2010 Attendee, 2013, and Basic 2013 allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."

Published: 2013-07-10 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-3129 is rated High Risk (67.7/100): CVSS High severity, with high exploitation likelihood (EPSS 51.65%, 98th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +2.30% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2013-3129

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-28 49.36% 51.65% +2.30%
2 2025-12-27 51.65% 49.36% -2.30%
3 2025-10-28 51.65%

Full EPSS history (24 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-3129

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.8 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
8.6 10.0 [email protected]

Weakness enumeration for CVE-2013-3129

Affected software / configurations for CVE-2013-3129

Vendor Product Version Raw CPE
microsoft .net_framework 3.0 cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*
microsoft .net_framework 3.5 cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
microsoft .net_framework 3.5.1 cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
microsoft .net_framework 4.0 cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:*
microsoft .net_framework 4.5 cpe:2.3:a:microsoft:.net_framework:4.5:*:*:*:*:*:*:*
microsoft lync 2010 cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*
microsoft lync 2010 cpe:2.3:a:microsoft:lync:2010:*:x64:*:*:*:*:*
microsoft lync 2010 cpe:2.3:a:microsoft:lync:2010:*:x86:*:*:*:*:*
microsoft lync 2013 cpe:2.3:a:microsoft:lync:2013:-:x64:*:*:*:*:*
microsoft lync 2013 cpe:2.3:a:microsoft:lync:2013:-:x86:*:*:*:*:*
microsoft lync_basic 2013 cpe:2.3:a:microsoft:lync_basic:2013:-:x64:*:*:*:*:*
microsoft lync_basic 2013 cpe:2.3:a:microsoft:lync_basic:2013:-:x86:*:*:*:*:*
microsoft office 2003 cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
microsoft office 2007 cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*
microsoft office 2010 cpe:2.3:a:microsoft:office:2010:sp1:x64:*:*:*:*:*
microsoft office 2010 cpe:2.3:a:microsoft:office:2010:sp1:x86:*:*:*:*:*
microsoft silverlight 5.0.60401.0 cpe:2.3:a:microsoft:silverlight:5.0.60401.0:*:*:*:*:*:*:*
microsoft silverlight 5.0.60818.0 cpe:2.3:a:microsoft:silverlight:5.0.60818.0:*:*:*:*:*:*:*
microsoft silverlight 5.0.60818.0 cpe:2.3:a:microsoft:silverlight:5.0.60818.0:rc:*:*:*:*:*:*
microsoft silverlight 5.0.61118.0 cpe:2.3:a:microsoft:silverlight:5.0.61118.0:*:*:*:*:*:*:*
microsoft silverlight 5.1.10411.0 cpe:2.3:a:microsoft:silverlight:5.1.10411.0:*:*:*:*:*:*:*
microsoft silverlight 5.1.20125.0 cpe:2.3:a:microsoft:silverlight:5.1.20125.0:*:*:*:*:*:*:*
microsoft visual_studio_.net 2003 cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*
microsoft windows_7 cpe:2.3:o:microsoft:windows_7:*:sp1:x64:*:*:*:*:*
microsoft windows_7 cpe:2.3:o:microsoft:windows_7:*:sp1:x86:*:*:*:*:*
microsoft windows_8 cpe:2.3:o:microsoft:windows_8:-:-:x64:*:*:*:*:*
microsoft windows_8 cpe:2.3:o:microsoft:windows_8:-:-:x86:*:*:*:*:*
microsoft windows_rt cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
microsoft windows_server_2003 cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:*:sp2:itanium:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:*:sp2:x64:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:*:sp2:x86:*:*:*:*:*
microsoft windows_server_2012 cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*

References for CVE-2013-3129

cvelogic Threat Intelligence