CVE-2010-1898
Summary
| CVE | CVE-2010-1898 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-11 18:47:50 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Microsoft | .net Framework | 2.0 | sp1 | All | All |
| Application | Microsoft | .net Framework | 2.0 | sp2 | All | All |
| Application | Microsoft | .net Framework | 3.5 | All | All | All |
| Application | Microsoft | .net Framework | 3.5 | sp1 | All | All |
| Application | Microsoft | .net Framework | 3.5.1 | All | All | All |
| Application | Microsoft | Silverlight | 2.0.31005.00 | All | All | All |
| Application | Microsoft | Silverlight | 2.0.40115.00 | All | All | All |
| Application | Microsoft | Silverlight | 3.0.40624.00 | All | All | All |
| Application | Microsoft | Silverlight | 3.0.40723.0 | All | All | All |
| Application | Microsoft | Silverlight | All | All | All | All |
| Application | Microsoft | Silverlight | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Technical Cyber Security Alert TA10-222A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Microsoft Security Bulletin MS10-060 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.