MS12-035: Vulnerabilities in .NET Framework Could Allow Remote Code Execution (2693777)

This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.


Synopsis :

The .NET Framework install on the remote Windows host could allow
arbitrary code execution.

Description :

The version of the .NET Framework installed on the remote host is
affected by multiple vulnerabilities in the serialization process.
Untrusted data is treated as trusted which could result in arbitrary
code execution.

See also :

http://technet.microsoft.com/en-us/security/Bulletin/MS12-035

Solution :

Microsoft has released a set of patches for .NET Framework 1.0, 1.1,
2.0, 3.0, 3.5, and 4.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.3
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 59043 ()

Bugtraq ID: 53356
53357

CVE ID: CVE-2012-0160
CVE-2012-0161