CVE-2013-0073

Description

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka WinForms Callback Elevation Vulnerability.

Risk Information

Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
59.169

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2789643) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2789643) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2789642) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2789642) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2789646) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2789646) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2789648) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2789648) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 (KB2789644)Windows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 (KB2789644) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2789645)Windows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2789645) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2789650) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2789650) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2789649) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2789649) x64 bases systemsWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13167Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2789643)
PATCH-13168Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2789643)
PATCH-13169Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2789642)
PATCH-13170Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2789642)
PATCH-13171Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2789646)
PATCH-13172Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2789646)
PATCH-13173Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2789648)
PATCH-13174Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2789648)
PATCH-13176Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 (KB2789644)
PATCH-13178Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2789645)
PATCH-13179Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2789650)
PATCH-13180Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2789650)
PATCH-13181Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2789649)
PATCH-13182Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2789649)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234