CVE-2013-0001
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 13.55% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-004
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15814
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-004
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15814
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.