PT-2011-3007 · Microsoft · .Net Framework

User31056

·

Publicado

2011-05-10

·

Atualizado

2024-10-17

·

CVE-2011-1271

CVSS v3.1

7.7

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 3.5 Gold and SP1 through 4.0
Description The issue allows context-dependent attackers to bypass intended access restrictions and execute arbitrary code by leveraging a crafted application, such as a crafted XAML browser application, a crafted ASP.NET application, or a crafted .NET Framework application. This can occur when the IsJITOptimizerDisabled setting is false. An attacker who successfully exploits this issue could take complete control of an affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft .NET Framework versions 3.5 Gold and SP1 through 4.0, consider disabling the JIT compiler optimization by setting IsJITOptimizerDisabled to true until a patch is available. As a temporary workaround, restrict the execution of crafted applications, such as XAML browser applications, ASP.NET applications, or .NET Framework applications, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1271

Produtos afetados

.Net Framework