CVE-2013-3903
Status: ModifiedMedium (4.7)—
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."
CVSS
- Version: 2.0
- Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C
- Base score: 4.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.00%
- Percentile among all scored CVEs: 80
- Score date: 10/11/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (4)
CWEs
- CWE-20
References
Raw JSON (NVD)
Show
{
"id": "CVE-2013-3903",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.7,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-12-11T00:55:03.757",
"references": [
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-101",
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-101",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka \"TrueType Font Parsing Vulnerability.\""
},
{
"lang": "es",
"value": "Error de indexación de array en win32k.sys en los drivers kernel-mode de Microsoft Windows 8, Windows Server 2012 Gold y R2, y Windows RT Gold y 8.1 permite a usuarios locales provocar una denegación de servicio (reinicio) a través de un archivo de fuente TrueType (TTF) manipulado, también conocido como \"Vulnerabilidad de análisis sintáctico de fuentes TrueType\"."
}
],
"lastModified": "2026-06-16T23:55:59.643",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_8:-:-:x64:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE8E7D74-0DCB-4633-B502-EDC2112229BA"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_8:-:-:x86:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DAA2E6F-A666-4136-8F6B-E35C313CAB2B"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABC7A32C-4A4A-4533-B42E-350E728ADFEB"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6CE5198-C498-4672-AF4C-77AB4BE06C5C"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:datacenter:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32BCD530-F6E2-4F9B-AD4C-7DF2BED00296"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:essentials:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1318333-EF3A-4DBA-8DD7-367BF843F70D"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:standard:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74B5E7C1-6C1D-4605-91CF-AF105EFA678D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@microsoft.com"
}