MS13-054: Description of the security update for Windows DirectWrite: July 9, 2013


View products that this article applies to.

Introduction

This update resolves a vulnerability that could allow remote code execution on a client system if a user opens a specially crafted document or visits a specially crafted webpage that embeds TrueType font files.

Summary

Microsoft has released security bulletin MS13-054. To view the complete security bulletin, go to one of the following Microsoft websites:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More information about this security update

Download information

This update is available for download from the Microsoft Download Center:

Windows Vista Service Pack 2 (32-bit)

Windows Vista Service Pack 2 (64-bit)

Windows Server 2008 Service Pack 2 (32-bit)

Windows Server 2008 Service Pack 2 (64-bit)

Windows 7 Service Pack 1 (32-bit)

Windows 7 Service Pack 1 (64-bit)

Windows Server 2008 R2 Service Pack 1 (64-bit)

Windows Server 2008 R2 Service Pack 1 (IA-64)

Windows 8 (32-bit)

Windows 8 (64-bit)

Windows Server 2012

Windows Server 2012 (Server Core)


Information about DirectWrite and this security update

By default, DirectWrite is not installed on supported editions of Windows Vista Service Pack 2. On this operating system, DirectWrite is installed as part of the Windows Graphics, Imaging, and XPS Library update, the Platform Update Supplement update, or the Update for DirectWrite and XPS update. This update is applicable only if any of these updates are installed on the computer.

Restart information

You must restart the computer after you install this security update.

Removal information

Note We do not recommend that you remove any security update.

For Windows Vista or Windows Server 2008 and later versions

To remove an update that is installed by Windows Update Stand-alone Installer (Wusa.exe), use the /Uninstall setup switch or click Control Panel, click System and Security, and then under Windows Update, click View installed updates. Then, select from the list of updates.

Security update replacement information

This security update replaces MS12-034: Description of the security update for DirectWrite in Windows: May 8, 2012.

The English (United States) version of this hotfix installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

Windows Vista and Windows Server 2008 file information notes

  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.

    Version

    Product

    Milestone

    Service branch

    6.0.6002.18xxx

    Windows Vista SP2 and Windows Server 2008 SP2

    SP2

    GDR

    6.0.6002.23xxx

    Windows Vista SP2 and Windows Server 2008 SP2

    SP2

    LDR

  • Service Pack 1 is integrated into the original release version of Windows Server 2008. Therefore, RTM milestone files apply only to Windows Vista. RTM milestone files have a 6.0.0000.xxxxxx version number.

  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.

  • The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.


For all supported x86-based versions of Windows Vista and of Windows Server 2008

File name

File version

File size

Date

Time

Platform

D2d1.dll

7.0.6002.18827

683,008

17-Apr-2013

10:24

x86

D2d1.dll

7.0.6002.23097

683,008

17-Apr-2013

10:14

x86

Fntcache.dll

7.0.6002.18827

798,208

17-Apr-2013

10:20

x86

Fntcache.dll

7.0.6002.23097

798,208

17-Apr-2013

10:10

x86

Dwrite.dll

7.0.6002.18827

1,069,056

17-Apr-2013

10:21

x86

Dwrite.dll

7.0.6002.23097

1,069,056

17-Apr-2013

10:10

x86

D3d10level9.dll

7.0.6002.18827

486,400

17-Apr-2013

10:47

x86

D3d10level9.dll

7.0.6002.23097

486,400

17-Apr-2013

10:33

x86

D3d10_1.dll

7.0.6002.18827

160,768

17-Apr-2013

12:30

x86

D3d10_1core.dll

7.0.6002.18827

219,648

17-Apr-2013

12:30

x86

D3d10_1.dll

7.0.6002.23097

160,768

17-Apr-2013

11:28

x86

D3d10_1core.dll

7.0.6002.23097

219,648

17-Apr-2013

11:28

x86

D3d10.dll

7.0.6002.18827

1,029,120

17-Apr-2013

12:30

x86

D3d10core.dll

7.0.6002.18827

189,952

17-Apr-2013

12:30

x86

D3d10.dll

7.0.6002.23097

1,029,120

17-Apr-2013

11:28

x86

D3d10core.dll

7.0.6002.23097

189,952

17-Apr-2013

11:28

x86

D3d10warp.dll

7.0.6002.18827

1,172,480

17-Apr-2013

10:48

x86

D3d10warp.dll

7.0.6002.23097

1,172,480

17-Apr-2013

10:34

x86

For all supported x64-based versions of Windows Vista and of Windows Server 2008

File name

File version

File size

Date

Time

Platform

D2d1.dll

7.0.6002.18827

834,048

17-Apr-2013

10:57

x64

D2d1.dll

7.0.6002.23097

834,048

17-Apr-2013

11:02

x64

Fntcache.dll

7.0.6002.18827

1,149,440

17-Apr-2013

10:53

x64

Fntcache.dll

7.0.6002.23097

1,149,440

17-Apr-2013

10:58

x64

Dwrite.dll

7.0.6002.18827

1,556,480

17-Apr-2013

10:53

x64

Dwrite.dll

7.0.6002.23097

1,556,480

17-Apr-2013

10:58

x64

D3d10level9.dll

7.0.6002.18827

566,272

17-Apr-2013

11:26

x64

D3d10level9.dll

7.0.6002.23097

566,272

17-Apr-2013

11:27

x64

D3d10_1.dll

7.0.6002.18827

196,096

17-Apr-2013

13:04

x64

D3d10_1core.dll

7.0.6002.18827

327,680

17-Apr-2013

13:04

x64

D3d10_1.dll

7.0.6002.23097

196,096

17-Apr-2013

12:32

x64

D3d10_1core.dll

7.0.6002.23097

327,680

17-Apr-2013

12:32

x64

D3d10.dll

7.0.6002.18827

1,268,224

17-Apr-2013

13:04

x64

D3d10core.dll

7.0.6002.18827

287,232

17-Apr-2013

13:04

x64

D3d10.dll

7.0.6002.23097

1,268,224

17-Apr-2013

12:32

x64

D3d10core.dll

7.0.6002.23097

287,232

17-Apr-2013

12:32

x64

D3d10warp.dll

7.0.6002.18827

2,002,944

17-Apr-2013

11:28

x64

D3d10warp.dll

7.0.6002.23097

2,002,944

17-Apr-2013

11:29

x64

D2d1.dll

7.0.6002.18827

683,008

17-Apr-2013

10:24

x86

D2d1.dll

7.0.6002.23097

683,008

17-Apr-2013

10:14

x86

Dwrite.dll

7.0.6002.18827

1,069,056

17-Apr-2013

10:21

x86

Dwrite.dll

7.0.6002.23097

1,069,056

17-Apr-2013

10:10

x86

D3d10level9.dll

7.0.6002.18827

486,400

17-Apr-2013

10:47

x86

D3d10level9.dll

7.0.6002.23097

486,400

17-Apr-2013

10:33

x86

D3d10_1.dll

7.0.6002.18827

160,768

17-Apr-2013

12:30

x86

D3d10_1core.dll

7.0.6002.18827

219,648

17-Apr-2013

12:30

x86

D3d10_1.dll

7.0.6002.23097

160,768

17-Apr-2013

11:28

x86

D3d10_1core.dll

7.0.6002.23097

219,648

17-Apr-2013

11:28

x86

D3d10.dll

7.0.6002.18827

1,029,120

17-Apr-2013

12:30

x86

D3d10core.dll

7.0.6002.18827

189,952

17-Apr-2013

12:30

x86

D3d10.dll

7.0.6002.23097

1,029,120

17-Apr-2013

11:28

x86

D3d10core.dll

7.0.6002.23097

189,952

17-Apr-2013

11:28

x86

D3d10warp.dll

7.0.6002.18827

1,172,480

17-Apr-2013

10:48

x86

D3d10warp.dll

7.0.6002.23097

1,172,480

17-Apr-2013

10:34

x86

Windows 7 and Windows Server 2008 R2 file information notes

  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:

    Version

    Product

    Milestone

    Service branch

    6.1.7601.18xxx

    Windows 7 and Windows Server 2008 R2

    SP1

    GDR

    6.1.7601.22xxx

    Windows 7 and Windows Server 2008 R2

    SP1

    LDR


  • The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.


For all supported x86-based versions of Windows 7

File name

File version

File size

Date

Time

Platform

Dwrite.dll

6.1.7601.18126

1,077,760

10-Apr-2013

05:02

x86

Dwrite.dll

6.1.7601.22296

1,077,760

10-Apr-2013

05:14

x86

Dwrite.dll

6.2.9200.16571

1,247,744

09-Apr-2013

23:34

x86

Dwrite.dll

6.2.9200.20675

1,247,744

10-Apr-2013

05:15

x86

For all supported x64-based versions of Windows 7 and of Windows Server 2008 R2

File name

File version

File size

Date

Time

Platform

Dwrite.dll

6.1.7601.18126

1,545,728

10-Apr-2013

05:45

x64

Dwrite.dll

6.1.7601.22296

1,545,728

10-Apr-2013

05:21

x64

Dwrite.dll

6.2.9200.16571

1,643,520

02-Apr-2013

22:51

x64

Dwrite.dll

6.2.9200.20675

1,643,520

10-Apr-2013

05:21

x64

Dwrite.dll

6.1.7601.18126

1,077,760

10-Apr-2013

05:02

x86

Dwrite.dll

6.1.7601.22296

1,077,760

10-Apr-2013

05:14

x86

Dwrite.dll

6.2.9200.16571

1,247,744

09-Apr-2013

23:34

x86

Dwrite.dll

6.2.9200.20675

1,247,744

10-Apr-2013

05:15

x86

For all supported IA-64-based versions of Windows Server 2008 R2

File name

File version

File size

Date

Time

Platform

Dwrite.dll

6.1.7601.18126

3,011,584

10-Apr-2013

04:35

IA-64

Dwrite.dll

6.1.7601.22296

3,012,096

10-Apr-2013

04:27

IA-64

Dwrite.dll

6.1.7601.18126

1,077,760

10-Apr-2013

05:02

x86

Dwrite.dll

6.1.7601.22296

1,077,760

10-Apr-2013

05:14

x86

Windows 8 and Windows Server 2012 file information notesImportant Windows 8 and Windows Server 2012 hotfixes are included in the same packages. However, only "Windows 8" is listed on the Hotfix Request page. To request the hotfix package that applies to one or both operating systems, select the hotfix that is listed under "Windows 8" on the page. Always refer to the "Applies To" section in articles to determine the actual operating system that each hotfix applies to.

  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.

    Version

    Product

    Milestone

    Service branch

    6.2.920 0.16 xxx

    Windows 8 and Windows Server 2012

    RTM

    GDR

    6.2.920 0.20 xxx

    Windows 8 and Windows Server 2012

    RTM

    LDR

  • The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.

For all supported x86-based versions of Windows 8

File name

File version

File size

Date

Time

Platform

Dwrite.dll

6.2.9200.16581

1,421,312

11-Apr-2013

22:30

x86

Dwrite.dll

6.2.9200.20685

1,417,216

11-Apr-2013

22:35

x86

For all supported x64-based versions of Windows 8 and of Windows Server 2012

File name

File version

File size

Date

Time

Platform

Dwrite.dll

6.2.9200.16579

1,838,080

11-Apr-2013

22:22

x64

Dwrite.dll

6.2.9200.20682

1,836,544

11-Apr-2013

23:16

x64

Dwrite.dll

6.2.9200.16581

1,421,312

11-Apr-2013

22:30

x86

Dwrite.dll

6.2.9200.20685

1,417,216

11-Apr-2013

22:35

x86



Applies toThis article applies to the following:

  • Windows 8

  • Windows RT

  • Windows Server 2012

  • Windows 7 Service Pack 1

  • Windows Server 2008 R2 Service Pack 1

  • Windows Vista Service Pack 2

  • Windows Server 2008 Service Pack 2

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×