CVE-2010-1898: Code Injection
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1898?
CVE-2010-1898 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2010-1898?
To fix CVE-2010-1898, update your Microsoft .NET Framework and Silverlight to the latest versions provided by Microsoft.
What software is affected by CVE-2010-1898?
CVE-2010-1898 affects Microsoft .NET Framework versions 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, 3.5.1 and Microsoft Silverlight versions 2 and 3 before 3.0.50611.0 on Windows.
Is CVE-2010-1898 exploitable?
Yes, CVE-2010-1898 is exploitable, allowing remote attackers to execute arbitrary code on affected systems.
What are the risks of not addressing CVE-2010-1898?
Failing to address CVE-2010-1898 can lead to severe risks including unauthorized access and full control over the impacted machines.