View products that this article applies to.

Introduction

This update resolves a vulnerability that could allow remote code execution on a client system if a user opens a specially crafted document or visits a specially crafted webpage that embeds TrueType font files.

Summary

Microsoft has released the security bulletin MS13-054. You can view the complete security bulletin by going to one of the following Microsoft websites:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft UpdateSecurity solutions for IT professionals: TechNet Security Troubleshooting and SupportHelp protect your computer that is running Windows from viruses and malware: Virus Solution and Security CenterLocal support according to your country: International Support

Download information

This update is available for download from the Microsoft Download Center:

http://go.microsoft.com/fwlink/?LinkID=306294

Prerequisites

To install this update, you must have Windows Installer 2.0 or a later version installed on the computer. To obtain the latest version of Windows Installer, click the following article number to view the article in the Microsoft Knowledge Base:

893803 Windows Installer 3.1 v2 (3.1.4000.2435) is available

Command-line switches for this update

For information about the various command-line switches that are supported by this update, click the following article number to view the article in the Microsoft Knowledge Base:

912203 Description of the command-line switches that are supported by a software installation package, an update package, or a hotfix package that was created by using Microsoft Self-Extractor

Restart information

You may have to restart the computer after you install this security update.In some cases, this update does not require a restart. If the required files are being used, this update will require a restart. If this behavior occurs, a message is displayed that advises you to restart the computer.To help reduce the possibility that a restart will be required, stop all affected services and close all applications that may use the affected files before you install this security update.See Why you may be prompted to restart your computer after you install a security update on a Windows-based computer for more information.

Removal information

Note We do not recommend that you remove any security update.To remove this update, use the Add or Remove Programs item in Control Panel.

Update replacement information

This update replaces MS09-062: Description of the security update for Microsoft Visual Studio 2003 Service Pack 1: October 13, 2009.

The English (United States) version of this update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

File name

File version

File size

Date

Time

Platform

Gdiplus.dll

5.2.6002.23084

1,748,992

10-Apr-2013

17:45

Not Applicable

Mso.dll

10.0.6885.0

9,812,624

17-May-2013

12:53

Not Applicable

Applies toThis article applies to the following:

  • Microsoft Visual Studio .NET 2003 Service Pack 1

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.