CVE-2009-0091: Code Injection
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0091?
CVE-2009-0091 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2009-0091?
To resolve CVE-2009-0091, you should apply the latest security updates provided by Microsoft for the affected .NET Framework versions.
Which systems are affected by CVE-2009-0091?
CVE-2009-0091 affects Microsoft .NET Framework versions 1.0, 1.1, 2.0, 2.0 SP1, 2.0 SP2, 3.5, and various versions of Windows, including Windows 2000, Server 2003, Server 2008, Vista, and XP.
What types of attacks could exploit CVE-2009-0091?
Attackers can exploit CVE-2009-0091 via crafted XAML browser applications (XBAP) or ASP.NET applications that leverage the vulnerability.
Is there a workaround for CVE-2009-0091 if I cannot apply the fix immediately?
While the most effective mitigation for CVE-2009-0091 is to apply the security updates, temporarily restricting access to .NET applications may help reduce the risk until a patch can be applied.