Threat Encyclopedia



This indicates an attack against a remote Code Execution vulnerability in Microsoft .NET Framework.
The vulnerability is caused when Entity Framework, a .NET Framework component, incorrectly restricts the path used for loading external libraries. An attacker could convince a user to open a legitimate file associated with the application built using ADO.NET that is located in the same network directory as a specially crafted dynamic link library file.

affected-products-logoAffected Products

Microsoft .NET Framework 1.0 Service Pack 3
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4


System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply patch, available from the web site

CVE References