Lucene search

K
cvelistMicrosoftCVELIST:CVE-2013-3171
HistoryJul 10, 2013 - 1:00 a.m.

CVE-2013-3171

2013-07-1001:00:00
microsoft
www.cve.org

7.3 High

AI Score

Confidence

Low

0.48 Medium

EPSS

Percentile

97.5%

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka “Delegate Serialization Vulnerability.”

7.3 High

AI Score

Confidence

Low

0.48 Medium

EPSS

Percentile

97.5%