CVE-2013-0002
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 25.12% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-004
- https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3E
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16343
- http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-004
- https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3E
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16343
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.