Lucene search

K
cve[email protected]CVE-2009-0091
HistoryOct 14, 2009 - 10:30 a.m.

CVE-2009-0091

2009-10-1410:30:00
CWE-94
web.nvd.nist.gov
52
microsoft
.net framework
type-equality constraint
vulnerability
security
nvd
cve-2009-0091

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.584 Medium

EPSS

Percentile

97.7%

Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka β€œMicrosoft .NET Framework Type Verification Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_2000sp4
AND
microsoft.net_frameworkMatch1.1sp1
OR
microsoft.net_frameworkMatch2.0sp1
OR
microsoft.net_frameworkMatch2.0sp2
Node
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008itanium
OR
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_server_2008sp2itanium
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2008Match-sp2
OR
microsoftwindows_server_2008Match-sp2x86
AND
microsoft.net_frameworkMatch1.1sp1
OR
microsoft.net_frameworkMatch2.0sp1
OR
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5
OR
microsoft.net_frameworkMatch3.5sp1
Node
microsoftwindows_vista
OR
microsoftwindows_vistax64
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistasp2
AND
microsoft.net_frameworkMatch1.1sp1
OR
microsoft.net_frameworkMatch2.0
OR
microsoft.net_frameworkMatch2.0sp1
OR
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5
OR
microsoft.net_frameworkMatch3.5sp1
Node
microsoft.net_frameworkMatch1.1sp1
AND
microsoftwindows_7Match-
OR
microsoftwindows_server_2008r2itanium
OR
microsoftwindows_server_2008r2x64
Node
microsoft.net_frameworkMatch1.0sp3
OR
microsoft.net_frameworkMatch1.1sp1
OR
microsoft.net_frameworkMatch2.0sp1
OR
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5
OR
microsoft.net_frameworkMatch3.5sp1
AND
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp3
OR
microsoftwindows_xpMatch-sp2x64

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.584 Medium

EPSS

Percentile

97.7%