Microsoft .NET Framework CVE-2012-2519 DLL Loading Arbitrary Code Execution Vulnerability
BID:56462
Info
Microsoft .NET Framework CVE-2012-2519 DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 56462 |
| Class: | Design Error |
| CVE: |
CVE-2012-2519 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2012 12:00AM |
| Updated: | Mar 19 2015 09:19AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.0 Microsoft .NET Framework 3.5 Microsoft .NET Framework 2.0 SP2 Microsoft .NET Framework 2.0 BETA Microsoft .NET Framework 2.0 Microsoft .NET Framework 1.1 SP1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.0 SP3 Microsoft .NET Framework 1.0 SP2 Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 Avaya Messaging Application Server 5.2 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft .NET Framework CVE-2012-2519 DLL Loading Arbitrary Code Execution Vulnerability
Microsoft .NET Framework is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location which contains a specially crafted Dynamic Link Library (DLL) file.
Attackers can exploit this issue remotely by placing the files in a remotely accessible SMB or WebDAV share location.
Successful exploits will compromise the application in the context of the currently logged-in user.
Microsoft .NET Framework is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location which contains a specially crafted Dynamic Link Library (DLL) file.
Attackers can exploit this issue remotely by placing the files in a remotely accessible SMB or WebDAV share location.
Successful exploits will compromise the application in the context of the currently logged-in user.
Exploit / POC
Microsoft .NET Framework CVE-2012-2519 DLL Loading Arbitrary Code Execution Vulnerability
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Microsoft .NET Framework CVE-2012-2519 DLL Loading Arbitrary Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft .NET Framework 2.0 SP2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 4.0
Microsoft .NET Framework 1.1 SP1
Microsoft .NET Framework 1.0 SP3
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft .NET Framework 2.0 SP2
-
Microsoft Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows X
http://www.microsoft.com/downloads/details.aspx?familyid=e7e75292-efcf -4c97-960c-958f81931cbf -
Microsoft Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and
http://www.microsoft.com/downloads/details.aspx?familyid=6d742523-5f51 -4db7-b05f-a9055b36b090
Microsoft .NET Framework 3.5
-
Microsoft Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012
http://www.microsoft.com/downloads/details.aspx?familyid=89faa423-42fa -48ff-be71-8fd58fa523a8
Microsoft .NET Framework 4.0
-
Microsoft Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, an
http://www.microsoft.com/downloads/details.aspx?familyid=f89c10fb-9f85 -47b6-8204-d970d7e84e33
Microsoft .NET Framework 1.1 SP1
-
Microsoft Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack
http://www.microsoft.com/downloads/details.aspx?familyid=efe0de22-8ca3 -474e-acda-7203bf66d0a3 -
Microsoft Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows XP, Windows Server 2003 (
http://www.microsoft.com/downloads/details.aspx?familyid=17a110d1-ef31 -4230-9f2a-0df190c28747
Microsoft .NET Framework 1.0 SP3
-
Microsoft Security Update for Microsoft .NET Framework 1.0 Service Pack 3 on Windows XP Service Pack 3 Tablet
http://www.microsoft.com/downloads/details.aspx?familyid=f5472e86-2b2f -42bd-abca-6adf84973efa
References
Microsoft .NET Framework CVE-2012-2519 DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Homepage (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- ASA-2012-480: (MS12-074) Vulnerabilities in .NET Framework (Avaya)
- Microsoft Security Bulletin MS12-074 (Microsoft)