Release date:
Updated on: 2013-01-10
Affected Systems:
Microsoft. NET Framework 4.x
Microsoft. NET Framework 3.x
Microsoft. NET Framework 2.x
Microsoft. NET Framework 1.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-0001
. NET is Microsoft's technology for implementing XML, Web Services, SOA (service-oriented architecture) and agility .. NET Framework is a software Framework developed by Microsoft and mainly runs on Microsoft Windows.
Microsoft. when processing pointers, the Windows Forms System Drawing namespace contains errors.. NET application, which can bypass CAS restrictions and leak sensitive information.
<* Source: vendor
Link: http://secunia.com/advisories/51777/
Http://www.microsoft.com/technet/security/bulletin/MS13-004.mspx
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS13-004) and patches for this:
MS13-004: Vulnerabilities in. NET Framework cocould Allow Elevation of Privilege (2769324)
Link: http://www.microsoft.com/technet/security/bulletin/MS13-004.mspx