CVE-2011-1271
7.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Exploitability: 2.2 / Impact: 5.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework JIT Optimization Vulnerability."
Affected (6)
Products: Microsoft: .net Framework
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 7 | All versions |
Microsoft Windows Server 2008 | Version r2 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp2 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 sp1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 2003 Server | All versions |
Microsoft Windows Server 2003 | All versions |
Microsoft Windows Server 2008 | All versions |
Microsoft Windows Vista | All versions |
Microsoft Windows Xp | All versions |
Related CWEs
References (6)
Source: secure@microsoft.com
Exploit
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.