CVE-2011-1845: High severity microsoft silverlight vulnerability
Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1845?
CVE-2011-1845 has a severity rating of moderate due to the potential for denial of service through memory consumption.
How do I fix CVE-2011-1845?
To mitigate CVE-2011-1845, update Microsoft Silverlight to version 4.0.60310.0 or later.
What types of applications are affected by CVE-2011-1845?
CVE-2011-1845 affects applications using Silverlight's DataGrid control that involve subscriptions to the INotifyDataErrorInfo.ErrorsChanged event.
Can CVE-2011-1845 be exploited remotely?
Yes, CVE-2011-1845 can be exploited remotely, leading to potential denial of service for users.
What versions of Silverlight are vulnerable to CVE-2011-1845?
CVE-2011-1845 affects Microsoft Silverlight versions 2.0-4.0.60129.0.