MS13-060: Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2850869)

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

It is possible to execute arbitrary code on the remote Windows host
using the Unicode Scripts Processor.

Description :

The version of Microsoft Windows installed on the remote host includes
a vulnerable version of the Unicode Script Processor, also known as
Uniscribe. Some font types are not parsed correctly, which can result
in memory corruption. An attacker could exploit this by tricking a user
into viewing a specially crafted web page or opening a file containing
malicious OpenType fonts, resulting in arbitrary code execution.

See also :

https://technet.microsoft.com/en-us/security/bulletin/ms13-060

Solution :

Microsoft has released a set of patches for Windows XP and 2003.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 69325 ()

Bugtraq ID: 61697

CVE ID: CVE-2013-3181