9.3
CVSSv2

CVE-2012-1895

Published: 14/11/2012 Updated: 07/12/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote malicious users to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net_framework 1.0

microsoft .net_framework 1.1

microsoft .net_framework 2.0

microsoft .net_framework 3.5.1

microsoft .net_framework 4.0