5.1
CVSSv2

CVE-2011-1271

Published: 10/05/2011 Updated: 07/12/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent malicious users to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework JIT Optimization Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net_framework 4.0

microsoft .net_framework 3.5.1

microsoft .net_framework 2.0

microsoft .net_framework 3.5

Exploits

source: wwwsecurityfocuscom/bid/47834/info The Microsoft NET Framework is prone to a remote code-execution vulnerability that affects the Just-In-Time (JIT) compiler optimization on x86 architectures Successful exploits may allow an attacker to execute arbitrary code in the context of the browser; this may aid in further attacks if ( ...