First published: Tue Feb 14 2012(Updated: )
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Microsoft .NET Framework | =2.0-sp2 | |
Microsoft .NET Framework | =3.5.1 | |
Microsoft .NET Framework | =4.0 | |
Any of | ||
Microsoft Windows 7 | ||
Microsoft Windows 7 | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Any of | ||
Microsoft Silverlight | =4.0.50524.00 | |
Microsoft Silverlight | =4.0.50826.0 | |
Microsoft Silverlight | =4.0.50917.0 | |
Microsoft Silverlight | =4.0.51204.0 | |
Microsoft Silverlight | =4.0.60129.0 | |
Microsoft Silverlight | =4.0.60310.0 | |
Microsoft Silverlight | =4.0.60531.0 | |
Microsoft Silverlight | =4.0.60831.0 | |
Microsoft Silverlight | =4.0.603310.0 | |
Microsoft Silverlight | =4.1.10111 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
Microsoft .NET Framework | =2.0-sp2 | |
Microsoft .NET Framework | =3.5.1 | |
Microsoft .NET Framework | =4.0 | |
Microsoft Windows 7 | ||
Microsoft Windows 7 | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Silverlight | =4.0.50524.00 | |
Microsoft Silverlight | =4.0.50826.0 | |
Microsoft Silverlight | =4.0.50917.0 | |
Microsoft Silverlight | =4.0.51204.0 | |
Microsoft Silverlight | =4.0.60129.0 | |
Microsoft Silverlight | =4.0.60310.0 | |
Microsoft Silverlight | =4.0.60531.0 | |
Microsoft Silverlight | =4.0.60831.0 | |
Microsoft Silverlight | =4.0.603310.0 | |
Microsoft Silverlight | =4.1.10111 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0014 has a critical severity rating, allowing attackers to execute arbitrary code remotely.
To fix CVE-2012-0014, apply the latest security updates for Microsoft .NET Framework and Silverlight.
CVE-2012-0014 affects Microsoft .NET Framework versions 2.0 SP2, 3.5.1, 4.0, and Silverlight 4 before 4.1.10111.
Yes, CVE-2012-0014 can be exploited via crafted XAML browser applications or ASP.NET applications.
CVE-2012-0014 involves vulnerabilities in Microsoft .NET Framework and Silverlight, affecting their handling of unmanaged object memory.