Microsoft .NET Framework CVE-2013-3171 Remote Privilege Escalation Vulnerability
BID:60937
Info
Microsoft .NET Framework CVE-2013-3171 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 60937 |
| Class: | Design Error |
| CVE: |
CVE-2013-3171 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2013 12:00AM |
| Updated: | Mar 19 2015 09:38AM |
| Credit: | James Forshaw of Context Information Security |
| Vulnerable: |
Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.0 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 Microsoft .NET Framework 2.0 SP2 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya CallPilot 0 |
| Not Vulnerable: | |
Discussion
Microsoft .NET Framework CVE-2013-3171 Remote Privilege Escalation Vulnerability
Microsoft .NET Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this vulnerability to bypass certain Code Access Security (CAS) restrictions and gain elevated privileges.
Microsoft .NET Framework is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this vulnerability to bypass certain Code Access Security (CAS) restrictions and gain elevated privileges.
Exploit / POC
Microsoft .NET Framework CVE-2013-3171 Remote Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft .NET Framework CVE-2013-3171 Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft .NET Framework 2.0 SP2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 4.0
Microsoft .NET Framework 4.5
Microsoft .NET Framework 3.5 SP1
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft .NET Framework 2.0 SP2
-
Microsoft Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows X
http://www.microsoft.com/downloads/details.aspx?familyid=7c62ca4f-63e5 -492a-85e1-d798ff339abd -
Microsoft Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and
http://www.microsoft.com/downloads/details.aspx?familyid=1301d925-2797 -444c-ab23-57f1087a19ba
Microsoft .NET Framework 3.5
-
Microsoft Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012
http://www.microsoft.com/downloads/details.aspx?familyid=89faa423-42fa -48ff-be71-8fd58fa523a8
Microsoft .NET Framework 4.0
-
Microsoft Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista and
http://www.microsoft.com/downloads/details.aspx?familyid=4f511dbf-f1bf -41ae-8ae0-0713ab46cfd7 -
Microsoft Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Wi
http://www.microsoft.com/downloads/details.aspx?familyid=49785308-e6a6 -4d05-a233-0c31eb4c7ca6
Microsoft .NET Framework 4.5
-
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 200
http://www.microsoft.com/downloads/details.aspx?familyid=ac525f53-aff2 -438a-a833-76cb8b563588 -
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012
http://www.microsoft.com/downloads/details.aspx?familyid=c9778a0f-264e -476b-8e40-742e0ab56200 -
Microsoft Security Update for Microsoft .NET Framework 4.5 on Windows Vista Service Pack 2, and Windows Server
http://www.microsoft.com/downloads/details.aspx?familyid=22681db1-e41b -47fb-9dd8-3112dd31a3e7
Microsoft .NET Framework 3.5 SP1
-
Microsoft Security Update for Microsoft .NET Framework 3.5 Service Pack 1 on Windows XP, Windows Server 2003,
http://www.microsoft.com/downloads/details.aspx?familyid=ed0e54c5-7847 -43b4-9e7c-dc514eb03fca -
Microsoft Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 20
http://www.microsoft.com/downloads/details.aspx?familyid=1de3c49d-177f -4c97-824a-eb0aeb01b40c
References
Microsoft .NET Framework CVE-2013-3171 Remote Privilege Escalation Vulnerability
References:
References:
- Microsoft .NET Framework Developer Center (Microsoft)
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS13-052 - Critical (Microsoft)
- MS13-052 Vulnerabilities in .NET Framework and Silverlight Could Allow Remote Co (Avaya)