CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS12-025 | Vulnerability in .NET Framework Could Allow Remote Code Execution (2671605) | Microsoft .NET | Critical | 11-04-2012 |
Technical Information
Brief overview of the risk:
The vulnerability could allow remote code execution on a client system if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs).
Detailed Information on the risk:
A remote code execution vulnerability exists in the way that Microsoft .NET Framework validates parameters when passing data to a function. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Further information on this exploit is available at : MS12-025
Affected Software
Microsoft .NET Framework 2.0Microsoft .NET Framework 4
Microsoft .NET Framework 1.1
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 1.0