This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.
The Windows kernel drivers on the remote host are affected by multiple
The remote Windows host has the following vulnerabilities :
- Multiple remote code execution vulnerabilities exist in
the way the Windows kernel-mode driver parses OpenType
and TrueType fonts. (CVE-2013-3128, CVE-2013-3894)
- Multiple privilege escalation vulnerabilities exist in
the Windows kernel-mode drivers. (CVE-2013-3879,
CVE-2013-3880, CVE-2013-3880, CVE-2013-3888)
- A privilege escalation vulnerability exists in
the Windows USB drivers. (CVE-2013-3200)
An attacker who successfully exploited these vulnerabilities could read
arbitrary amounts of kernel memory or gain elevated privileges.
Note that the update was re-offered for Windows 7 and 2008 R2 as of
January 14, 2014.
See also :
Microsoft has released a set of patches for Windows XP, 2003, Vista,
2008, 7, 2008 R2, 8, Windows RT, and 2012.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 70333 ()
Bugtraq ID: 62819628216282362828628306283162833
CVE ID: CVE-2013-3128CVE-2013-3200CVE-2013-3879CVE-2013-3880CVE-2013-3881CVE-2013-3888CVE-2013-3894
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.