MS13-060: Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2850869)

This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.


Synopsis :

It is possible to execute arbitrary code on the remote Windows host
using the Unicode Scripts Processor.

Description :

The version of Microsoft Windows installed on the remote host includes
a vulnerable version of the Unicode Script Processor, also known as
Uniscribe. Some font types are not parsed correctly, which can result
in memory corruption. An attacker could exploit this by tricking a user
into viewing a specially crafted web page or opening a file containing
malicious OpenType fonts, resulting in arbitrary code execution.

See also :

https://technet.microsoft.com/library/security/ms13-060

Solution :

Microsoft has released a set of patches for Windows XP and 2003.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 69325 ()

Bugtraq ID: 61697

CVE ID: CVE-2013-3181

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial