The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microsoft
Published: 2013-07-10T01:00:00
Updated: 2024-08-06T16:00:10.161Z
Reserved: 2013-04-17T00:00:00
Link: CVE-2013-3171
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-07-10T03:46:10.590
Modified: 2024-11-21T01:53:07.127
Link: CVE-2013-3171
Redhat
No data.