PT-2011-3007 · Microsoft · .Net Framework
User31056
·
Published
2011-05-10
·
Updated
2024-10-17
·
CVE-2011-1271
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 3.5 Gold and SP1 through 4.0
Description
The issue allows context-dependent attackers to bypass intended access restrictions and execute arbitrary code by leveraging a crafted application, such as a crafted XAML browser application, a crafted ASP.NET application, or a crafted .NET Framework application. This can occur when the IsJITOptimizerDisabled setting is false. An attacker who successfully exploits this issue could take complete control of an affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft .NET Framework versions 3.5 Gold and SP1 through 4.0, consider disabling the JIT compiler optimization by setting IsJITOptimizerDisabled to true until a patch is available. As a temporary workaround, restrict the execution of crafted applications, such as XAML browser applications, ASP.NET applications, or .NET Framework applications, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
.Net Framework