Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-3171
HistoryJul 10, 2013 - 3:46 a.m.

Design/Logic Flaw

2013-07-1003:46:00
PRIOn knowledge base
www.prio-n.com
2

8 High

AI Score

Confidence

Low

0.48 Medium

EPSS

Percentile

97.5%

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka “Delegate Serialization Vulnerability.”

8 High

AI Score

Confidence

Low

0.48 Medium

EPSS

Percentile

97.5%