Lucene search

K
cve[email protected]CVE-2013-3171
HistoryJul 10, 2013 - 3:46 a.m.

CVE-2013-3171

2013-07-1003:46:10
CWE-94
web.nvd.nist.gov
29
microsoft
.net framework
serialization
security
vulnerability
delegate serialization
code execution
nvd
cve-2013-3171

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.48 Medium

EPSS

Percentile

97.5%

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka “Delegate Serialization Vulnerability.”

Affected configurations

NVD
Node
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5
OR
microsoft.net_frameworkMatch3.5sp1
OR
microsoft.net_frameworkMatch3.5.1
OR
microsoft.net_frameworkMatch4.0
OR
microsoft.net_frameworkMatch4.5

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.48 Medium

EPSS

Percentile

97.5%