← Back

CVE-2013-3132

nvd nist
Published: Jul 10, 2013Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."

Affected (7)

1 product
.net Framework
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 1.0 sp3
Version 1.1 sp1
Version 2.0 sp2
Version 3.5.1
Version 3.5
Version 4.0
Version 4.5

References (6)

Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.