Microsoft .NET Framework CVE-2013-3132 Remote Privilege Escalation Vulnerability
BID:60933
Info
Microsoft .NET Framework CVE-2013-3132 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 60933 |
| Class: | Design Error |
| CVE: |
CVE-2013-3132 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2013 12:00AM |
| Updated: | Mar 19 2015 08:41AM |
| Credit: | James Forshaw of Context Information Security |
| Vulnerable: |
Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.0 Microsoft .NET Framework 3.5 Microsoft .NET Framework 2.0 SP2 Microsoft .NET Framework 1.1 SP1 Microsoft .NET Framework 1.0 SP3 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya CallPilot 0 |
| Not Vulnerable: | |
Discussion
Microsoft .NET Framework CVE-2013-3132 Remote Privilege Escalation Vulnerability
Microsoft .NET Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this vulnerability to bypass certain Code Access Security (CAS) restrictions and gain elevated privileges.
Microsoft .NET Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this vulnerability to bypass certain Code Access Security (CAS) restrictions and gain elevated privileges.
Exploit / POC
Microsoft .NET Framework CVE-2013-3132 Remote Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft .NET Framework CVE-2013-3132 Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft .NET Framework 2.0 SP2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 4.0
Microsoft .NET Framework 1.1 SP1
Microsoft .NET Framework 1.0 SP3
Microsoft .NET Framework 4.5
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft .NET Framework 2.0 SP2
-
Microsoft Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows X
http://www.microsoft.com/downloads/details.aspx?familyid=7c62ca4f-63e5 -492a-85e1-d798ff339abd -
Microsoft Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and
http://www.microsoft.com/downloads/details.aspx?familyid=1301d925-2797 -444c-ab23-57f1087a19ba
Microsoft .NET Framework 3.5
-
Microsoft Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012
http://www.microsoft.com/downloads/details.aspx?familyid=89faa423-42fa -48ff-be71-8fd58fa523a8
Microsoft .NET Framework 4.0
-
Microsoft Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista and
http://www.microsoft.com/downloads/details.aspx?familyid=4f511dbf-f1bf -41ae-8ae0-0713ab46cfd7 -
Microsoft Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Wi
http://www.microsoft.com/downloads/details.aspx?familyid=49785308-e6a6 -4d05-a233-0c31eb4c7ca6
Microsoft .NET Framework 1.1 SP1
-
Microsoft Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack
http://www.microsoft.com/downloads/details.aspx?familyid=fdf06985-0c87 -4c21-83d1-123becfe36ac -
Microsoft Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows XP, Windows Server 2003 (
http://www.microsoft.com/downloads/details.aspx?familyid=aa80223d-56e6 -4847-9f03-883b717817a4
Microsoft .NET Framework 1.0 SP3
-
Microsoft Security Update for Microsoft .NET Framework 1.0 Service Pack 3 on Windows XP Service Pack 3 Tablet
http://www.microsoft.com/downloads/details.aspx?familyid=ef572517-3430 -43c4-a72d-32f28bf99f9e
Microsoft .NET Framework 4.5
-
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 200
http://www.microsoft.com/downloads/details.aspx?familyid=ac525f53-aff2 -438a-a833-76cb8b563588 -
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012
http://www.microsoft.com/downloads/details.aspx?familyid=c9778a0f-264e -476b-8e40-742e0ab56200 -
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows Vista Service Pack 2, and Windows Server
http://www.microsoft.com/downloads/details.aspx?familyid=22681db1-e41b -47fb-9dd8-3112dd31a3e7
References
Microsoft .NET Framework CVE-2013-3132 Remote Privilege Escalation Vulnerability
References:
References:
- Microsoft .NET Framework Developer Center (Microsoft)
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS13-052 - Critical (Microsoft)
- MS13-052 Vulnerabilities in .NET Framework and Silverlight Could Allow Remote Co (Avaya)