9.3
CVSSv2

CVE-2010-1898

Published: 11/08/2010 Updated: 12/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 prior to 3.0.50611.0 on Windows and prior to 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote malicious users to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net framework 2.0

microsoft .net framework 3.5

microsoft .net framework 3.5.1

microsoft silverlight

microsoft silverlight 3.0.40723.0

microsoft silverlight 3.0.40624.00

microsoft silverlight 2.0.40115.00

microsoft silverlight 2.0.31005.00

microsoft silverlight 3.0.40818.0