First published: Tue Jul 10 2007(Updated: )
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows Server 2003 | ||
Microsoft Windows Vista | ||
Microsoft Windows XP | ||
Microsoft .NET Framework 4 | =1.0 | |
Microsoft .NET Framework 4 | =1.1 | |
Microsoft .NET Framework 4 | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0043 is rated as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2007-0043, update to a non-vulnerable version of the .NET Framework.
CVE-2007-0043 affects Microsoft .NET Framework versions 1.0, 1.1, and 2.0 on Windows 2000, XP, Server 2003, and Vista.
CVE-2007-0043 is classified as a buffer overflow vulnerability in the Just In Time Compiler service.
Yes, CVE-2007-0043 can be exploited remotely if an attacker can lure a user into opening a specially crafted file.