CVE-2009-0090: Critical severity Microsoft Windows 2000 vulnerability
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0090?
CVE-2009-0090 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2009-0090?
To fix CVE-2009-0090, you should apply the security update released by Microsoft as part of MS09-061.
What versions of the Microsoft .NET Framework are affected by CVE-2009-0090?
CVE-2009-0090 affects Microsoft .NET Framework versions 1.0 SP3, 1.1 SP1, 2.0 SP1, and other related versions.
Can CVE-2009-0090 be exploited through web applications?
Yes, CVE-2009-0090 can be exploited through crafted XAML browser applications (XBAP) and ASP.NET applications.
What systems are impacted by CVE-2009-0090?
CVE-2009-0090 impacts various versions of Microsoft Windows, including Windows 2000, Windows XP, Windows Server 2003, and more.