PT-2009-2790 · Microsoft · .Net Framework

Pavel Minaev

·

Published

2009-10-14

·

Updated

2023-12-07

·

CVE-2009-0090

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 1.0 SP3 through 2.0 SP1
Description The issue allows remote attackers to obtain unintended access to stack memory and execute arbitrary code via crafted applications, including XAML browser applications, ASP.NET applications, or .NET Framework applications. A remote code execution vulnerability exists in the Microsoft .NET Framework, which could allow a malicious Microsoft .NET application to obtain a managed pointer to stack memory that is no longer used, leading to arbitrary unmanaged code execution.
Recommendations For Microsoft .NET Framework versions 1.0 SP3 through 2.0 SP1, update to a version that properly validates .NET verifiable code to prevent remote attackers from obtaining unintended access to stack memory. As a temporary workaround, consider restricting the execution of crafted .NET applications to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0090

Affected Products

.Net Framework