MS15-101: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3089662)

High Nessus Plugin ID 85847


The version of the .NET Framework installed on the remote host is affected by multiple vulnerabilities.


The remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities in the Microsoft .NET Framework :

- An elevation of privilege vulnerability exists due to improper validation of the number of objects in memory before they are copied into an array. A remote, unauthenticated attacker can exploit this to bypass Code Access Security (CAS) restrictions by convincing a user to run an untrusted .NET application or to visit a website containing a malicious XAML browser application.

- A denial of service vulnerability exists due to improper handling of specially crafted requests to an ASP .NET server. A remote, unauthenticated attacker can exploit this to degrade performance. (CVE-2015-2526)


Microsoft has released a set of patches for .NET Framework 2.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6.

See Also

Plugin Details

Severity: High

ID: 85847

File Name: smb_nt_ms15-101.nasl

Version: $Revision: 1.8 $

Type: local

Agent: windows

Published: 2015/09/08

Modified: 2017/07/24

Dependencies: 13855, 57033, 51351

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:.net_framework

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2015/09/08

Vulnerability Publication Date: 2015/09/08

Reference Information

CVE: CVE-2015-2504, CVE-2015-2526

BID: 76560, 76567

OSVDB: 127218

MSFT: MS15-101

MSKB: 3074228, 3074229, 3074230, 3074231, 3074232, 3074233, 3074541, 3074543, 3074544, 3074545, 3074547, 3074548, 3074549, 3074550, 3074552, 3074553, 3074554, 3081455

IAVA: 2015-A-0213