Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Microsoft .NET Framework Security Bypass Vulnerability

Information

Severity

Severity

Medium

Family

Family

Windows

CVSSv2 Base

CVSSv2 Base

5.1

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

12 years ago

Modified

Modified

5 years ago

Summary

The host is installed with Microsoft .NET Framework and is prone to security bypass vulnerability This NVT has been replaced by OID:1.3.6.1.4.1.25623.1.0.902522.

Insight

Insight

The flaw is due to an error in the JIT compiler, when 'IsJITOptimizerDisabled' is set to false, fails to handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a crafted application.

Affected Software

Affected Software

Microsoft .NET Framework versions before 4 beta 2.

Solution

Solution

Upgrade to Microsoft .NET Framework version 4 beta 2 or later.

Common Vulnerabilities and Exposures (CVE)