← Back

CVE-2011-3417

nvd nist
Published: Dec 30, 2011Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."

Affected (13)

5 products
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
All versions
All versions
Microsoft
All versions
All versions
All versions
All versions
Version r2
Microsoft
All versions
All versions
Microsoft
All versions
Version sp3 unknown

Related CWEs

Timeline

No history available yet.