‫ Microsoft .NET Framework Two Serialization Vulnerabilities

IRCAD2012051907
ID: IRCAD2012051907
Release Date: 2012-05-08
Criticality level: Highly critical
 
Software:
Microsoft .NET Framework 1.x
Microsoft .NET Framework 2.x
Microsoft .NET Framework 3.x
Microsoft .NET Framework 4.x
 
Description:
Two vulnerabilities have been reported in Microsoft .NET Framework, which can be exploited by malicious people to compromise a user's system.
1) An error within the .NET Framework does not properly serialize user input and can be exploited to treat untrusted input as trusted.
2) An error within the .NET Framework does not properly handle exceptions when serializing objects and can be exploited via partially trusted assemblies.
Successful exploitation of the vulnerabilities allows execution of arbitrary code.
 
Solution
Apply patches.
 
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
 
References:
MS12-035 (KB2693777, KB2604042, KB2604044, KB2604092, KB2604110, KB2604111, KB2604121, KB2604078, KB2604094, KB2604105, KB2604115, KB2604114):
 
Secunia:
 

نظرات

بدون نظر
شما برای نظر دادن باید وارد شوید

نوشته

 
تاریخ ایجاد: 20 اردیبهشت 1391

امتیاز

امتیاز شما
تعداد امتیازها:0