CVE-2012-0014: Code Injection
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0014?
CVE-2012-0014 has a critical severity rating, allowing attackers to execute arbitrary code remotely.
How do I fix CVE-2012-0014?
To fix CVE-2012-0014, apply the latest security updates for Microsoft .NET Framework and Silverlight.
Which versions of software are affected by CVE-2012-0014?
CVE-2012-0014 affects Microsoft .NET Framework versions 2.0 SP2, 3.5.1, 4.0, and Silverlight 4 before 4.1.10111.
Can CVE-2012-0014 be exploited through web applications?
Yes, CVE-2012-0014 can be exploited via crafted XAML browser applications or ASP.NET applications.
What are the components involved in CVE-2012-0014?
CVE-2012-0014 involves vulnerabilities in Microsoft .NET Framework and Silverlight, affecting their handling of unmanaged object memory.