9.3

CVE-2011-1253

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft.Net Framework Version1.0 Updatesp3
   MicrosoftWindows Xp Version2005 Updatesp3 Editionmedia_center
   MicrosoftWindows Xp Version2005 Updatesp3 Editiontablet_pc
Microsoft.Net Framework Version1.1 Updatesp1
   MicrosoftWindows 2003 Server Updatesp2
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Server 2008 Updatesp2 Editionx32
   MicrosoftWindows Server 2008 Updatesp2 Editionx64
   MicrosoftWindows Server 2008 Version- Updatesp2 Editionitanium
   MicrosoftWindows Vista Updatesp2
   MicrosoftWindows Xp Updatesp3
   MicrosoftWindows Xp Version- Updatesp2 Editionx64
Microsoft.Net Framework Version2.0 Updatesp2
   MicrosoftWindows 2003 Server Updatesp2
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Server 2008 Updatesp2 Editionx32
   MicrosoftWindows Server 2008 Updatesp2 Editionx64
   MicrosoftWindows Server 2008 Version- Updatesp2 Editionitanium
   MicrosoftWindows Vista Updatesp2
   MicrosoftWindows Xp Updatesp3
   MicrosoftWindows Xp Version- Updatesp2 Editionx64
Microsoft.Net Framework Version3.5.1
   MicrosoftWindows 7 Version-
   MicrosoftWindows 7 Version- Updatesp1 Editionx64
   MicrosoftWindows 7 Version- Updatesp1 Editionx86
   MicrosoftWindows Server 2008 Versionr2 Editionitanium
   MicrosoftWindows Server 2008 Versionr2 Editionx64
Microsoft.Net Framework Version4.0
   MicrosoftWindows 2003 Server Updatesp2
   MicrosoftWindows 7 Version- Updatesp1 Editionx64
   MicrosoftWindows 7 Version- Updatesp1 Editionx86
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Server 2008 Updatesp2 Editionx32
   MicrosoftWindows Server 2008 Updatesp2 Editionx64
   MicrosoftWindows Server 2008 Version- Updatesp2 Editionitanium
   MicrosoftWindows Server 2008 Versionr2 Editionitanium
   MicrosoftWindows Server 2008 Versionr2 Editionx64
   MicrosoftWindows Vista Updatesp2
   MicrosoftWindows Xp Updatesp3
   MicrosoftWindows Xp Version- Updatesp2 Editionx64
MicrosoftSilverlight Version4.0.60531.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.5% 0.952
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C