CVE-2013-3134

Published Jul 10, 2013

Last updated 6 years ago

Overview

Description
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
Source
secure@microsoft.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
9.3
Impact score
10
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-94

Evaluator

Comment
-
Impact
Per: http://technet.microsoft.com/en-us/security/bulletin/ms13-052#section6 'Systems running 32-bit versions of Windows are not affected by this vulnerability.'
Solution
Per: http://technet.microsoft.com/en-us/security/bulletin/ms13-052#section6 'Systems running 32-bit versions of Windows are not affected by this vulnerability.'

Configurations