Revision Date: | 2014-08-18 | Version: | 28 | Title: | .NET Framework Array Offset Vulnerability | Description: | Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability." | Family: | windows | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2011-0664
| Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows XP
| Product(s): | Microsoft .NET Framework Microsoft Silverlight 4
| Definition Synopsis | .NET Framework 3.5 on XP x86/x64, Server 2003 x86/x64/ia64. KB2478656 XP x86/x64, Server 2003 x86/x64/ia64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
OR Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
OR Microsoft Windows Server 2003 (ia64) Gold is installed
AND Microsoft .NET Framework 3.5 Original Release is installed
AND the version of System.dll is less than 2.0.50727.1889
OR .NET Framework 2.0 SP2 and .NET Framework 3.5 SP1 on Windows XP x86/x64, Windows Server 2003 x86/x64/ia64. KB2478658
Windows XP x86/x64, Windows Server 2003 x86/x64/ia64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
OR Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
OR Microsoft Windows Server 2003 (ia64) Gold is installed
AND Microsoft .NET Framework 2.0 Service Pack 2 is installed
AND GDR or LDR Service branch
the version of System.dll is less than 2.0.50727.3620
OR LDR
the version of System.dll is less than 2.0.50727.5071
AND the version of System.dll is greater than or equal to 2.0.50727.5000
OR .NET Framework 2.0 SP1 and .NET Framework 3.5 on Vista x86/x64, Server 2008 x86/x64/ia64.(KB2478657)
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft .NET Framework 2.0 Service Pack 1 is installed
AND the version of System.dll is less than 2.0.50727.1889
OR .NET Framework 2.0 SP2 and .NET Framework 3.5 SP1 on Vista x86/x64, Server 2008 x86/x64/ia64. (KB2478659)
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft .NET Framework 2.0 Service Pack 2 is installed
AND GDR or LDR Service branch
the version of System.dll is less than 2.0.50727.3620
OR LDR
the version of System.dll is less than 2.0.50727.5071
AND the version of System.dll is greater than or equal to 2.0.50727.5000
OR .NET Framework 2.0 SP2 and .NET Framework 3.5 SP1 on Vista x86/x64, Server 2008 x86/x64/ia64. (KB2478660)
Vista x86/x64, Server 2008 x86/x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
AND Microsoft .NET Framework 2.0 Service Pack 2 is installed
AND GDR or LDR Service branch
the version of System.dll is less than 2.0.50727.4212
OR LDR
the version of System.dll is less than 2.0.50727.5071
AND the version of System.dll is greater than or equal to 2.0.50727.5000
OR .NET Framework 3.5.1 on Windows 7 x86/x64, Server 2008 r2 x64/ia64. (KB2478661)
Windows 7 x86/x64, Server 2008 r2 x64/ia64
Microsoft Windows 7 (32-bit) is installed
OR Microsoft Windows 7 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
AND Microsoft .NET Framework 3.5 SP1 is installed
AND GDR or LDR Service branch
the version of System.dll is less than 2.0.50727.4957
OR LDR
the version of System.dll is less than 2.0.50727.5071
AND the version of System.dll is greater than or equal to 2.0.50727.5000
OR .NET Framework 3.5.1 on Windows 7 x86/x64, Server 2008 R2 x64/ia64. (KB2478662)
Windows 7 x86/x64, Server 2008 R2 x64/ia64
Microsoft Windows 7 (32-bit) is installed
OR Microsoft Windows 7 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
AND Microsoft .NET Framework 3.5 SP1 is installed
AND GDR or LDR Service branch
the version of System.dll is less than 2.0.50727.5442
OR LDR
the version of System.dll is less than 2.0.50727.5650
AND the version of System.dll is greater than or equal to 2.0.50727.5600
OR .NET Framework 4.0 on Windows XP x86/x64, Server 2003 x86/x64/ia64, Vista x86/x64, Server 2008 x86/x64/ia64, Windows 7 x86/x64, Server 2008 r2 x64/ia64. (KB2478663)
Windows XP x86/x64, Windows Server 2003 x86/x64/ia64, Vista x86/x64, Server 2008 x86/x64/ia64, Windows 7 x86/x64, Server 2008 r2 x64/ia64
Microsoft Windows XP (32-bit) is installed
OR Microsoft Windows XP x64 is installed
OR Microsoft Windows Server 2003 (32-bit) is installed
OR Microsoft Windows Server 2003 (x64) is installed
OR Microsoft Windows Server 2003 (ia64) Gold is installed
OR Microsoft Windows Vista (32-bit) is installed
OR Microsoft Windows Vista x64 Edition is installed
OR Microsoft Windows Server 2008 (32-bit) is installed
OR Microsoft Windows Server 2008 (64-bit) is installed
OR Microsoft Windows Server 2008 (ia-64) is installed
OR Microsoft Windows 7 (32-bit) is installed
OR Microsoft Windows 7 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 x64 Edition is installed
OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
AND Microsoft .NET Framework 4.0 is installed
AND GDR or LDR Service branch
the version of System.dll is less than 4.0.30319.232
OR LDR
the version of System.dll is less than 4.0.30319.447
AND the version of System.dll is greater than or equal to 4.0.30319.400
|
|