CVE-2010-3958: Input Validation
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3958?
CVE-2010-3958 is classified as a critical vulnerability that allows for remote code execution.
How do I fix CVE-2010-3958?
To mitigate CVE-2010-3958, install the latest Microsoft security updates for the .NET Framework.
Which versions are affected by CVE-2010-3958?
CVE-2010-3958 affects Microsoft .NET Framework versions 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0.
What type of attack is possible with CVE-2010-3958?
CVE-2010-3958 allows an attacker to execute arbitrary code through crafted XAML browser applications or ASP.NET applications.
Is it necessary to use a firewall with CVE-2010-3958?
While a firewall can provide additional protection, the key mitigative action for CVE-2010-3958 is applying relevant software patches.