Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft .NET Framework vulnerability could allow remote code execution


Report ID: MS201206003
Date Published: 13 June 2012

Criticality: Critical
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4




Summary

A vulnerability in Microsoft .NET Framework places an unprotected system at risk of being controlled by a remote attacker.



Detailed Description

Microsoft has released a security update to address a vulnerability in .NET Framework. The vulnerability was caused by improper execution of a function pointer, and upon successful exploit, it could allow an attacker to take control of an affected system.

This issue has been fixed through the update by making correction on the way that .NET Framework validates data passed to function pointers. Users are recommended to install this latest update to protect their system from potential exploit attempt.



CVE Reference

CVE-2012-1855



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-038)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.