PT-2009-2790 · Microsoft · .Net Framework
Pavel Minaev
·
Published
2009-10-14
·
Updated
2023-12-07
·
CVE-2009-0090
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 1.0 SP3 through 2.0 SP1
Description
The issue allows remote attackers to obtain unintended access to stack memory and execute arbitrary code via crafted applications, including XAML browser applications, ASP.NET applications, or .NET Framework applications. A remote code execution vulnerability exists in the Microsoft .NET Framework, which could allow a malicious Microsoft .NET application to obtain a managed pointer to stack memory that is no longer used, leading to arbitrary unmanaged code execution.
Recommendations
For Microsoft .NET Framework versions 1.0 SP3 through 2.0 SP1, update to a version that properly validates .NET verifiable code to prevent remote attackers from obtaining unintended access to stack memory.
As a temporary workaround, consider restricting the execution of crafted .NET applications to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework