CVE Database
/

CVE-2010-1898

Back to search

CVE-2010-1898

Published: Aug 11, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

TA10-222A
third-party-advisory
x_refsource_CERT
MS10-060
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:12033
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now