Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-1898 | First vendor Publication | 2010-08-11 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1898 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12033 | |||
Oval ID: | oval:org.mitre.oval:def:12033 | ||
Title: | Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability | ||
Description: | The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-1898 | Version: | 13 |
Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 | Product(s): | Microsoft .NET Framework |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 5 |
OpenVAS Exploits
Date | Description |
---|---|
2010-08-11 | Name : Microsoft .NET Common Language Runtime Remote Code Execution Vulnerability (2... File : nvt/secpod_ms10-060.nasl |
2005-11-03 | Name : foxweb CGI File : nvt/foxweb_dll.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
66993 | Microsoft .NET Framework / Silverlight CLR Virtual Delegate Handling Remote C... Microsoft .NET Framework and Silverlight contain a flaw related to the Common Language Runtime failing to properly handle virtual method delegations and interfaces. This may allow a context-dependent attacker to use a crafted ASP.NET application, XAML browser application or .NET Framework application to execute arbitrary code. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft .NET CreateDelegate method arbitrary code execution attempt RuleID : 17118 - Revision : 7 - Type : FILE-EXECUTABLE |
2014-01-10 | Microsoft SilverLight ImageSource remote code execution attempt RuleID : 17114 - Revision : 15 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-08-11 | Name : The Microsoft .NET Common Language Runtime and/or Microsoft Silverlight have ... File : smb_nt_ms10-060.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:52 |
|
2024-11-28 12:22:00 |
|
2024-08-02 12:13:45 |
|
2024-08-02 01:03:43 |
|
2024-02-02 01:13:21 |
|
2024-02-01 12:03:39 |
|
2023-09-05 12:12:25 |
|
2023-09-05 01:03:30 |
|
2023-09-02 12:12:28 |
|
2023-09-02 01:03:32 |
|
2023-08-12 12:14:49 |
|
2023-08-12 01:03:32 |
|
2023-08-11 12:12:31 |
|
2023-08-11 01:03:40 |
|
2023-08-06 12:12:03 |
|
2023-08-06 01:03:34 |
|
2023-08-04 12:12:08 |
|
2023-08-04 01:03:35 |
|
2023-07-14 12:12:04 |
|
2023-07-14 01:03:33 |
|
2023-03-29 01:13:49 |
|
2023-03-28 12:03:39 |
|
2022-10-11 12:10:46 |
|
2022-10-11 01:03:21 |
|
2021-05-04 12:11:36 |
|
2021-04-22 01:12:13 |
|
2020-11-24 12:06:02 |
|
2020-05-23 00:25:50 |
|
2018-10-13 00:22:57 |
|
2017-09-19 09:23:48 |
|
2016-06-29 00:13:01 |
|
2016-04-26 19:49:27 |
|
2014-02-17 10:55:34 |
|
2014-01-19 21:26:52 |
|
2013-05-10 23:25:13 |
|