Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-0163Improper Input Validation in Microsoft NET Framework

Severity
9.3CRITICALNVD
EPSS
54.1%
top 1.98%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 10
Latest updateMay 4

Description

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmicrosoft/net_framework7 versions+6

🔴Vulnerability Details

2
GHSA
GHSA-85wj-fjj7-c42p: Microsoft2022-05-04
CVEList
CVE-2012-0163: Microsoft2012-04-10

💥Exploits & PoCs

1
Exploit-DB
Microsoft .NET Framework EncoderParameter - Integer Overflow (MS12-025)2012-04-24
CVE-2012-0163 — Improper Input Validation in Microsoft | cvebase