CVE-2012-0160: Input Validation
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0160?
CVE-2012-0160 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2012-0160?
To fix CVE-2012-0160, upgrade the .NET Framework to a supported version that includes security updates.
What versions of .NET Framework are affected by CVE-2012-0160?
CVE-2012-0160 affects Microsoft .NET Framework versions 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4.0.
What are the potential attacks associated with CVE-2012-0160?
Remote attackers can exploit CVE-2012-0160 through a crafted XAML browser application or a manipulated .NET Framework application.
Is there any workaround for CVE-2012-0160?
There are no effective workarounds for CVE-2012-0160 other than upgrading to a patched version of the .NET Framework.