PT-2009-2791 · Microsoft · .Net Framework

Jeroen Frijters

·

Published

2009-10-14

·

Updated

2023-12-07

·

CVE-2009-0091

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 2.0 through 3.5
Description A remote code execution issue exists due to the improper enforcement of a type-equality constraint in .NET verifiable code. This allows remote attackers to execute arbitrary code via crafted applications, including XAML browser applications (XBAP), ASP.NET applications, or .NET Framework applications. The issue can be exploited by a malicious Microsoft .NET application bypassing a type equality check, leading to arbitrary unmanaged code execution by casting an object of one type into another type.
Recommendations For Microsoft .NET Framework versions 2.0 through 3.5, update to a version that properly enforces type-equality constraints to prevent arbitrary code execution.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0091

Affected Products

.Net Framework