Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-1855

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2012-1855
Last Modified 06 Mar 2013 11:53:55
Published 12 Jun 2012 06:55:01
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-1855

Summary

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."

Vulnerable Systems

Application

  • Microsoft .net Framework 2.0

  • Microsoft .net Framework 3.5.1

  • Microsoft .net Framework 4.0


References

MS - MS12-038

CERT - TA12-164A

Related Patches

MS12-038 Security Update for .NET Framework 2.0 SP2 on Windows Vista SP2 and Windows Server 2008 SP2 x86 (KB2686833)

MS12-038 Security Update for .NET Framework 3.5.1 on Windows 7 x86 (KB2686830)

MS12-038 Security Update for .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 for x64 (KB2686830)

MS12-038 2706726 2686827 Security Update for .NET Framework 4.0 (All Languages)

MS12-038 2706726 2686828 Security Update for .NET Framework 2.0 SP2 (All Languages)

MS12-038 Security Update for .NET Framework 2.0 SP2 on Windows Vista SP2 and Windows Server 2008 SP2 for x64 (KB2686833)

MS12-038 Security Update for Microsoft .NET Framework 4 on XP, Server 2003, Vista, Win 7, Server 2008 x86 (KB2686827)

MS12-038 Security Update for Microsoft .NET Framework 2.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2686828)

MS12-038 Security Update for .NET 4 on XP, Server 2003, Vista, Win 7, Server 2008, Server 2008 R2 for x64 (KB2686827)

MS12-038 Security Update for Microsoft .NET Framework 2.0 SP2 on Windows Server 2003 and Windows XP x64 (KB2686828)


Last Updated: 27 May 2016 10:47:11