Introduction
This update resolves a vulnerability that could allow remote code execution on a client system if a user opens a specially crafted document or visits a specially crafted webpage that embeds TrueType font files.
Summary
Microsoft has released security bulletin MS13-054. To view the complete security bulletin, go to one of the following Microsoft websites:
-
Home users:
http://www.microsoft.com/security/pc-security/updates.aspxSkip the details: Download the updates for your home computer or laptop from the Microsoft Update website now:
-
IT professionals:
How to obtain help and support for this security update
Help installing updates: Support for Microsoft Update Security solutions for IT professionals: TechNet Security Troubleshooting and Support Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center Local support according to your country: International Support
More information about this security update
Download information
This update is available for download from the Microsoft Download Center:
Windows Vista Service Pack 2 (32-bit) Windows Vista Service Pack 2 (64-bit) Windows Server 2008 Service Pack 2 (32-bit) Windows Server 2008 Service Pack 2 (64-bit) Windows 7 Service Pack 1 (32-bit) Windows 7 Service Pack 1 (64-bit) Windows Server 2008 R2 Service Pack 1 (64-bit) Windows Server 2008 R2 Service Pack 1 (IA-64) Windows 8 (32-bit) Windows 8 (64-bit) Windows Server 2012 Windows Server 2012 (Server Core)
Information about DirectWrite and this security update
By default, DirectWrite is not installed on supported editions of Windows Vista Service Pack 2. On this operating system, DirectWrite is installed as part of the Windows Graphics, Imaging, and XPS Library update, the Platform Update Supplement update, or the Update for DirectWrite and XPS update. This update is applicable only if any of these updates are installed on the computer.
Restart information
You must restart the computer after you install this security update.
Removal information
Note We do not recommend that you remove any security update.
For Windows Vista or Windows Server 2008 and later versions
To remove an update that is installed by Windows Update Stand-alone Installer (Wusa.exe), use the /Uninstall setup switch or click Control Panel, click System and Security, and then under Windows Update, click View installed updates. Then, select from the list of updates.
Security update replacement information
This security update replaces MS12-034: Description of the security update for DirectWrite in Windows: May 8, 2012.
The English (United States) version of this hotfix installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.
Windows Vista and Windows Server 2008 file information notes
-
The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.
Version
Product
Milestone
Service branch
6.0.6002.18xxx
Windows Vista SP2 and Windows Server 2008 SP2
SP2
GDR
6.0.6002.23xxx
Windows Vista SP2 and Windows Server 2008 SP2
SP2
LDR
-
Service Pack 1 is integrated into the original release version of Windows Server 2008. Therefore, RTM milestone files apply only to Windows Vista. RTM milestone files have a 6.0.0000.xxxxxx version number.
-
GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
-
The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.
For all supported x86-based versions of Windows Vista and of Windows Server 2008
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
D2d1.dll |
7.0.6002.18827 |
683,008 |
17-Apr-2013 |
10:24 |
x86 |
D2d1.dll |
7.0.6002.23097 |
683,008 |
17-Apr-2013 |
10:14 |
x86 |
Fntcache.dll |
7.0.6002.18827 |
798,208 |
17-Apr-2013 |
10:20 |
x86 |
Fntcache.dll |
7.0.6002.23097 |
798,208 |
17-Apr-2013 |
10:10 |
x86 |
Dwrite.dll |
7.0.6002.18827 |
1,069,056 |
17-Apr-2013 |
10:21 |
x86 |
Dwrite.dll |
7.0.6002.23097 |
1,069,056 |
17-Apr-2013 |
10:10 |
x86 |
D3d10level9.dll |
7.0.6002.18827 |
486,400 |
17-Apr-2013 |
10:47 |
x86 |
D3d10level9.dll |
7.0.6002.23097 |
486,400 |
17-Apr-2013 |
10:33 |
x86 |
D3d10_1.dll |
7.0.6002.18827 |
160,768 |
17-Apr-2013 |
12:30 |
x86 |
D3d10_1core.dll |
7.0.6002.18827 |
219,648 |
17-Apr-2013 |
12:30 |
x86 |
D3d10_1.dll |
7.0.6002.23097 |
160,768 |
17-Apr-2013 |
11:28 |
x86 |
D3d10_1core.dll |
7.0.6002.23097 |
219,648 |
17-Apr-2013 |
11:28 |
x86 |
D3d10.dll |
7.0.6002.18827 |
1,029,120 |
17-Apr-2013 |
12:30 |
x86 |
D3d10core.dll |
7.0.6002.18827 |
189,952 |
17-Apr-2013 |
12:30 |
x86 |
D3d10.dll |
7.0.6002.23097 |
1,029,120 |
17-Apr-2013 |
11:28 |
x86 |
D3d10core.dll |
7.0.6002.23097 |
189,952 |
17-Apr-2013 |
11:28 |
x86 |
D3d10warp.dll |
7.0.6002.18827 |
1,172,480 |
17-Apr-2013 |
10:48 |
x86 |
D3d10warp.dll |
7.0.6002.23097 |
1,172,480 |
17-Apr-2013 |
10:34 |
x86 |
For all supported x64-based versions of Windows Vista and of Windows Server 2008
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
D2d1.dll |
7.0.6002.18827 |
834,048 |
17-Apr-2013 |
10:57 |
x64 |
D2d1.dll |
7.0.6002.23097 |
834,048 |
17-Apr-2013 |
11:02 |
x64 |
Fntcache.dll |
7.0.6002.18827 |
1,149,440 |
17-Apr-2013 |
10:53 |
x64 |
Fntcache.dll |
7.0.6002.23097 |
1,149,440 |
17-Apr-2013 |
10:58 |
x64 |
Dwrite.dll |
7.0.6002.18827 |
1,556,480 |
17-Apr-2013 |
10:53 |
x64 |
Dwrite.dll |
7.0.6002.23097 |
1,556,480 |
17-Apr-2013 |
10:58 |
x64 |
D3d10level9.dll |
7.0.6002.18827 |
566,272 |
17-Apr-2013 |
11:26 |
x64 |
D3d10level9.dll |
7.0.6002.23097 |
566,272 |
17-Apr-2013 |
11:27 |
x64 |
D3d10_1.dll |
7.0.6002.18827 |
196,096 |
17-Apr-2013 |
13:04 |
x64 |
D3d10_1core.dll |
7.0.6002.18827 |
327,680 |
17-Apr-2013 |
13:04 |
x64 |
D3d10_1.dll |
7.0.6002.23097 |
196,096 |
17-Apr-2013 |
12:32 |
x64 |
D3d10_1core.dll |
7.0.6002.23097 |
327,680 |
17-Apr-2013 |
12:32 |
x64 |
D3d10.dll |
7.0.6002.18827 |
1,268,224 |
17-Apr-2013 |
13:04 |
x64 |
D3d10core.dll |
7.0.6002.18827 |
287,232 |
17-Apr-2013 |
13:04 |
x64 |
D3d10.dll |
7.0.6002.23097 |
1,268,224 |
17-Apr-2013 |
12:32 |
x64 |
D3d10core.dll |
7.0.6002.23097 |
287,232 |
17-Apr-2013 |
12:32 |
x64 |
D3d10warp.dll |
7.0.6002.18827 |
2,002,944 |
17-Apr-2013 |
11:28 |
x64 |
D3d10warp.dll |
7.0.6002.23097 |
2,002,944 |
17-Apr-2013 |
11:29 |
x64 |
D2d1.dll |
7.0.6002.18827 |
683,008 |
17-Apr-2013 |
10:24 |
x86 |
D2d1.dll |
7.0.6002.23097 |
683,008 |
17-Apr-2013 |
10:14 |
x86 |
Dwrite.dll |
7.0.6002.18827 |
1,069,056 |
17-Apr-2013 |
10:21 |
x86 |
Dwrite.dll |
7.0.6002.23097 |
1,069,056 |
17-Apr-2013 |
10:10 |
x86 |
D3d10level9.dll |
7.0.6002.18827 |
486,400 |
17-Apr-2013 |
10:47 |
x86 |
D3d10level9.dll |
7.0.6002.23097 |
486,400 |
17-Apr-2013 |
10:33 |
x86 |
D3d10_1.dll |
7.0.6002.18827 |
160,768 |
17-Apr-2013 |
12:30 |
x86 |
D3d10_1core.dll |
7.0.6002.18827 |
219,648 |
17-Apr-2013 |
12:30 |
x86 |
D3d10_1.dll |
7.0.6002.23097 |
160,768 |
17-Apr-2013 |
11:28 |
x86 |
D3d10_1core.dll |
7.0.6002.23097 |
219,648 |
17-Apr-2013 |
11:28 |
x86 |
D3d10.dll |
7.0.6002.18827 |
1,029,120 |
17-Apr-2013 |
12:30 |
x86 |
D3d10core.dll |
7.0.6002.18827 |
189,952 |
17-Apr-2013 |
12:30 |
x86 |
D3d10.dll |
7.0.6002.23097 |
1,029,120 |
17-Apr-2013 |
11:28 |
x86 |
D3d10core.dll |
7.0.6002.23097 |
189,952 |
17-Apr-2013 |
11:28 |
x86 |
D3d10warp.dll |
7.0.6002.18827 |
1,172,480 |
17-Apr-2013 |
10:48 |
x86 |
D3d10warp.dll |
7.0.6002.23097 |
1,172,480 |
17-Apr-2013 |
10:34 |
x86 |
Windows 7 and Windows Server 2008 R2 file information notes
-
The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
Version
Product
Milestone
Service branch
6.1.7601.18xxx
Windows 7 and Windows Server 2008 R2
SP1
GDR
6.1.7601.22xxx
Windows 7 and Windows Server 2008 R2
SP1
LDR
-
The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.
For all supported x86-based versions of Windows 7
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
Dwrite.dll |
6.1.7601.18126 |
1,077,760 |
10-Apr-2013 |
05:02 |
x86 |
Dwrite.dll |
6.1.7601.22296 |
1,077,760 |
10-Apr-2013 |
05:14 |
x86 |
Dwrite.dll |
6.2.9200.16571 |
1,247,744 |
09-Apr-2013 |
23:34 |
x86 |
Dwrite.dll |
6.2.9200.20675 |
1,247,744 |
10-Apr-2013 |
05:15 |
x86 |
For all supported x64-based versions of Windows 7 and of Windows Server 2008 R2
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
Dwrite.dll |
6.1.7601.18126 |
1,545,728 |
10-Apr-2013 |
05:45 |
x64 |
Dwrite.dll |
6.1.7601.22296 |
1,545,728 |
10-Apr-2013 |
05:21 |
x64 |
Dwrite.dll |
6.2.9200.16571 |
1,643,520 |
02-Apr-2013 |
22:51 |
x64 |
Dwrite.dll |
6.2.9200.20675 |
1,643,520 |
10-Apr-2013 |
05:21 |
x64 |
Dwrite.dll |
6.1.7601.18126 |
1,077,760 |
10-Apr-2013 |
05:02 |
x86 |
Dwrite.dll |
6.1.7601.22296 |
1,077,760 |
10-Apr-2013 |
05:14 |
x86 |
Dwrite.dll |
6.2.9200.16571 |
1,247,744 |
09-Apr-2013 |
23:34 |
x86 |
Dwrite.dll |
6.2.9200.20675 |
1,247,744 |
10-Apr-2013 |
05:15 |
x86 |
For all supported IA-64-based versions of Windows Server 2008 R2
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
Dwrite.dll |
6.1.7601.18126 |
3,011,584 |
10-Apr-2013 |
04:35 |
IA-64 |
Dwrite.dll |
6.1.7601.22296 |
3,012,096 |
10-Apr-2013 |
04:27 |
IA-64 |
Dwrite.dll |
6.1.7601.18126 |
1,077,760 |
10-Apr-2013 |
05:02 |
x86 |
Dwrite.dll |
6.1.7601.22296 |
1,077,760 |
10-Apr-2013 |
05:14 |
x86 |
Windows 8 and Windows Server 2012 file information notesImportant Windows 8 and Windows Server 2012 hotfixes are included in the same packages. However, only "Windows 8" is listed on the Hotfix Request page. To request the hotfix package that applies to one or both operating systems, select the hotfix that is listed under "Windows 8" on the page. Always refer to the "Applies To" section in articles to determine the actual operating system that each hotfix applies to.
-
The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.
Version
Product
Milestone
Service branch
6.2.920 0.16 xxx
Windows 8 and Windows Server 2012
RTM
GDR
6.2.920 0.20 xxx
Windows 8 and Windows Server 2012
RTM
LDR
-
The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.
For all supported x86-based versions of Windows 8
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
Dwrite.dll |
6.2.9200.16581 |
1,421,312 |
11-Apr-2013 |
22:30 |
x86 |
Dwrite.dll |
6.2.9200.20685 |
1,417,216 |
11-Apr-2013 |
22:35 |
x86 |
For all supported x64-based versions of Windows 8 and of Windows Server 2012
File name |
File version |
File size |
Date |
Time |
Platform |
---|---|---|---|---|---|
Dwrite.dll |
6.2.9200.16579 |
1,838,080 |
11-Apr-2013 |
22:22 |
x64 |
Dwrite.dll |
6.2.9200.20682 |
1,836,544 |
11-Apr-2013 |
23:16 |
x64 |
Dwrite.dll |
6.2.9200.16581 |
1,421,312 |
11-Apr-2013 |
22:30 |
x86 |
Dwrite.dll |
6.2.9200.20685 |
1,417,216 |
11-Apr-2013 |
22:35 |
x86 |
Applies toThis article applies to the following:
-
Windows 8
-
Windows RT
-
Windows Server 2012
-
Windows 7 Service Pack 1
-
Windows Server 2008 R2 Service Pack 1
-
Windows Vista Service Pack 2
-
Windows Server 2008 Service Pack 2