CVE-2012-0014
published 2012-02-14CVE-2012-0014: Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged…
PriorityP351high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
28.17%
97.9th percentile
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-25c7-5442-g7pq: Microsoft
ghsa_unreviewed·2022-05-04
CVE-2012-0014 [HIGH] CWE-94 GHSA-25c7-5442-g7pq: Microsoft
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
VMware
VMware vCenter Operations, CapacityIQ, and Movie Decoder security updates
vendor_vmware·2012-10-04·CVSS 6.9
CVE-2012-4897 [MEDIUM] VMware vCenter Operations, CapacityIQ, and Movie Decoder security updates
VMSA-2012-0014: VMware vCenter Operations, CapacityIQ, and Movie Decoder security updates
a. VMware Movie Decoder Installer binary planting vulnerability The installer of the VMware Movie Decoder has a binary planting vulnerability. An attacker who can write their malicious executable to the same folder as where the installer of the Movie Decoder is located may be able to run their code when the installation is started. VMware would like to thank Mitja Kolsek of ACROS Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-4897 to this issue. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product Movie Decoder Product Version 7.x Running on Windows Replace with/ Apply Patch Movie D
No detection rules found.
No public exploits indexed.
http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13972http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13972
2012-02-14
Published