CVE-2012-0176: Double Free
Published May 9, 2012
·Updated
Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "Silverlight Double-Free Vulnerability."
Affected Software
12 affected components
Microsoft Silverlight=4.0.50401.0
Microsoft Silverlight=4.0.50524.00
Microsoft Silverlight=4.0.50826.0
Microsoft Silverlight=4.0.50917.0
Microsoft Silverlight=4.0.51204.0
Microsoft Silverlight=4.0.60129.0
Microsoft Silverlight=4.0.60310.0
Microsoft Silverlight=4.0.60531.0
Microsoft Silverlight=4.0.60831.0
Microsoft Silverlight=4.0.603310.0
Microsoft Silverlight=4.1.10111
Microsoft Silverlight=4.1.10111.0
Event History
May 9, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0176?
CVE-2012-0176 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2012-0176?
To fix CVE-2012-0176, update Microsoft Silverlight to a version that is 4.1.10329 or higher.
3
What products are affected by CVE-2012-0176?
CVE-2012-0176 affects several versions of Microsoft Silverlight 4 prior to 4.1.10329.
4
What type of vulnerability is CVE-2012-0176?
CVE-2012-0176 is classified as a double free vulnerability.
5
Can CVE-2012-0176 be exploited remotely?
Yes, CVE-2012-0176 can be exploited remotely via crafted XAML glyphs.