This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.
The version of the .NET Framework installed on the remote host is
affected by multiple vulnerabilities.
The remote Windows host is running a version of Microsoft .NET
Framework that is affected by multiple vulnerabilities :
- An information disclosure vulnerability exists in the
way the Windows Forms in .NET Framework handle pointers
to unmanaged memory locations. (CVE-2013-0001)
- A buffer overflow vulnerability in a Windows Form method
in the .NET Framework exists that could be exploited to
gain elevated privileges. (CVE-2013-0002)
- A method in the S.DS.P namespace of the .NET Framework is
affected by a buffer overflow vulnerability which could
be exploited to gain elevated privileges.
- The way the .NET Framework validates permissions of
certain objects in memory has a flaw that could be
exploited to gain elevated privileges. (CVE-2013-0004).
See also :
Microsoft has released a set of patches for the .NET Framework on
Windows XP, 2003, Vista, 2008, 7, 2008 R2, 8, and 2012.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 63422 ()
Bugtraq ID: 57113571145712457126
CVE ID: CVE-2013-0001CVE-2013-0002CVE-2013-0003CVE-2013-0004
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.