First published: Wed May 09 2012(Updated: )
Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "Silverlight Double-Free Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Silverlight | =4.0.50401.0 | |
Microsoft Silverlight | =4.0.50524.00 | |
Microsoft Silverlight | =4.0.50826.0 | |
Microsoft Silverlight | =4.0.50917.0 | |
Microsoft Silverlight | =4.0.51204.0 | |
Microsoft Silverlight | =4.0.60129.0 | |
Microsoft Silverlight | =4.0.60310.0 | |
Microsoft Silverlight | =4.0.60531.0 | |
Microsoft Silverlight | =4.0.60831.0 | |
Microsoft Silverlight | =4.0.603310.0 | |
Microsoft Silverlight | =4.1.10111 | |
Microsoft Silverlight | =4.1.10111.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0176 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2012-0176, update Microsoft Silverlight to a version that is 4.1.10329 or higher.
CVE-2012-0176 affects several versions of Microsoft Silverlight 4 prior to 4.1.10329.
CVE-2012-0176 is classified as a double free vulnerability.
Yes, CVE-2012-0176 can be exploited remotely via crafted XAML glyphs.