CVE-2013-3903: Microsoft Windows 8

Medium severity, CVSS 4.7. EPSS: 2% chance of exploitation in the next 30 days.

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."

Affected products

  • Microsoft Windows 8: affected versions not specified
  • Microsoft Windows Rt: affected versions not specified
  • Microsoft Windows Rt 8.1: affected versions not specified
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only

Published 2013-12-11. Last modified 2026-06-16.