Microsoft .NET Framework CVE-2012-4777 Remote Privilege Escalation Vulnerability
BID:56464
Info
Microsoft .NET Framework CVE-2012-4777 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 56464 |
| Class: | Design Error |
| CVE: |
CVE-2012-4777 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2012 12:00AM |
| Updated: | Mar 19 2015 09:38AM |
| Credit: | James Forshaw of Context Information Security |
| Vulnerable: |
Microsoft .NET Framework 4.0 Avaya Messaging Application Server 5.2 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft .NET Framework CVE-2012-4777 Remote Privilege Escalation Vulnerability
Microsoft .NET Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges within the application and obtain unauthorized access to the sensitive information.
Microsoft .NET Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges within the application and obtain unauthorized access to the sensitive information.
Exploit / POC
Microsoft .NET Framework CVE-2012-4777 Remote Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft .NET Framework CVE-2012-4777 Remote Privilege Escalation Vulnerability
Solution:
Updates are available; please see the references for more information.
Microsoft .NET Framework 4.0
Microsoft .NET Framework 4.5
Solution:
Updates are available; please see the references for more information.
Microsoft .NET Framework 4.0
-
Microsoft Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, an
http://www.microsoft.com/downloads/details.aspx?familyid=f89c10fb-9f85 -47b6-8204-d970d7e84e33
Microsoft .NET Framework 4.5
-
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 200
http://www.microsoft.com/downloads/details.aspx?familyid=ca52497c-8023 -42de-b707-2bc1bcee4579 -
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012
http://www.microsoft.com/downloads/details.aspx?familyid=c9778a0f-264e -476b-8e40-742e0ab56200 -
Microsoft Update for Windows 8 (KB2756872)
http://www.microsoft.com/downloads/details.aspx?familyid=b120a7a2-0eff -41d6-981e-60e5ecd55869 -
Microsoft Update for Windows 8 for x64-based Systems (KB2756872)
http://www.microsoft.com/downloads/details.aspx?familyid=c7a417e6-72e5 -4087-bb89-fb8e7f57894c -
Microsoft Update for Windows Server 2012 (KB2756872)
http://www.microsoft.com/downloads/details.aspx?familyid=0a7da3d1-a0ac -42a2-9929-b6d831deb9e3
References
Microsoft .NET Framework CVE-2012-4777 Remote Privilege Escalation Vulnerability
References:
References:
- Microsoft .NET Framework Developer Center (Microsoft)
- Microsoft Homepage (Microsoft)
- ASA-2012-480: (MS12-074) Vulnerabilities in .NET Framework (Avaya)
- Microsoft Security Bulletin MS12-074 (Microsoft)