PT-2014-1683 · Microsoft · Silverlight 5 Developer Runtime+1

Publicado

2014-03-11

·

Atualizado

2018-10-12

·

CVE-2014-0319

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Silverlight versions 5 through 5.1.30214.0 Microsoft Silverlight 5 Developer Runtime versions 5 through 5.1.30214.0
Description The issue exists due to the incorrect implementation of Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) in the Silverlight security feature. This allows an attacker to bypass DEP/ASLR protection mechanisms, enabling remote execution of arbitrary code.
Recommendations For Microsoft Silverlight versions 5 through 5.1.30214.0, update to version 5.1.30214.0 or later. For Microsoft Silverlight 5 Developer Runtime versions 5 through 5.1.30214.0, update to version 5.1.30214.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00630
CVE-2014-0319

Produtos afetados

Silverlight
Silverlight 5 Developer Runtime