Lucene search

K
cve[email protected]CVE-2012-0014
HistoryFeb 14, 2012 - 10:55 p.m.

CVE-2012-0014

2012-02-1422:55:01
CWE-94
web.nvd.nist.gov
105
cve-2012-0014
microsoft .net framework
memory restriction
remote code execution
xbap
asp.net
silverlight

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.286 Low

EPSS

Percentile

96.9%

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka โ€œ.NET Framework Unmanaged Objects Vulnerability.โ€

Affected configurations

NVD
Node
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5.1
OR
microsoft.net_frameworkMatch4.0
AND
microsoftwindows_7x64
OR
microsoftwindows_7x86
OR
microsoftwindows_7sp1x64
OR
microsoftwindows_7sp1x86
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2008sp2x86
OR
microsoftwindows_server_2008Matchr2itanium
OR
microsoftwindows_server_2008Matchr2x64
OR
microsoftwindows_vistasp2
OR
microsoftwindows_xpsp3
Node
microsoftsilverlightMatch4.0.50524.00
OR
microsoftsilverlightMatch4.0.50826.0
OR
microsoftsilverlightMatch4.0.50917.0
OR
microsoftsilverlightMatch4.0.51204.0
OR
microsoftsilverlightMatch4.0.60129.0
OR
microsoftsilverlightMatch4.0.60310.0
OR
microsoftsilverlightMatch4.0.60531.0
OR
microsoftsilverlightMatch4.0.60831.0
OR
microsoftsilverlightMatch4.0.603310.0
OR
microsoftsilverlightMatch4.1.10111
AND
applemac_os_x
OR
microsoftwindows

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.286 Low

EPSS

Percentile

96.9%