CVE-2012-4777: Critical severity Microsoft .NET Framework vulnerability
The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "WPF Reflection Optimization Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4777?
CVE-2012-4777 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2012-4777?
To mitigate CVE-2012-4777, users should apply the latest security updates released by Microsoft for the .NET Framework.
Who is affected by CVE-2012-4777?
CVE-2012-4777 affects users of Microsoft .NET Framework versions 4.0 and 4.5 across several Microsoft operating systems.
What types of attacks can exploit CVE-2012-4777?
CVE-2012-4777 can be exploited through crafted XAML browser applications (XBAP) or malicious .NET applications.
Is there a workaround for CVE-2012-4777?
Currently, the best workaround for CVE-2012-4777 is to avoid using untrusted applications and to keep the .NET Framework updated.