9.3
CVE-2012-4776
- EPSS 24.76%
- Veröffentlicht 14.11.2012 00:55:01
- Zuletzt bearbeitet 16.06.2026 23:45:42
- Erkennungen
The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Framework Version 2.0 Update sp2
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ .Net Framework Version 3.5.1
Microsoft ≫ .Net Framework Version 4.0
Microsoft ≫ Windows 7 Edition x64
Microsoft ≫ Windows 7 Edition x86
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update r2 Edition itanium
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows 7 Edition x86
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update r2 Edition itanium
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ .Net Framework Version 3.5
Microsoft ≫ .Net Framework Version 4.5
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 24.76% | 0.976 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.us-cert.gov/cas/techalerts/TA12-318A.html
http://secunia.com/advisories/51236
http://www.securitytracker.com/id?1027753
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-074
http://osvdb.org/87266
http://www.securityfocus.com/bid/56463
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15810