Microsoft .NET Bugs Let Remote Users Execute Arbitrary Commands, Access User Accounts, and Redirect Users
|
|
SecurityTracker Alert ID: 1026479 |
|
SecurityTracker URL: http://securitytracker.com/id/1026479
|
|
CVE Reference:
CVE-2011-3415, CVE-2011-3416, CVE-2011-3417
(Links to External Site)
|
Updated: Dec 30 2011
|
Original Entry Date: Dec 29 2011
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, 4
|
Description:
Several vulnerabilities were reported in Microsoft .NET. A remote user can execute arbitrary commands on the target application. A remote user can redirect users. A remote user can access a target user's account.
A remote user can exploit a flaw in the verification of return URLs during forms authentication to redirect the target user to an arbitrary web site [CVE-2011-3415]. Irene Abezgauz of Seeker reported this vulnerability.
A remote user with a registered account on the target ASP.NET application can submit a specially crafted request using that account to exploit an authentication flaw and gain access to the target user's account [CVE-2011-3416]. K. Gudinavicius and m. of SEC Consult reported this vulnerability.
A remote user can exploit a flaw in the handling of cached content when Forms Authentication is used with sliding expiry to execute arbitrary commands on the target site in the context of the target user [CVE-2011-3417]. Oliver Dewdney of LBi reported this vulnerability.
|
Impact:
A remote user can execute arbitrary commands on the target system.
A remote user can access a target user's account.
A remote user can redirect users to arbitrary sites.
|
Solution:
The vendor has issued a fix.
A patch matrix is available in the vendor's advisory.
The Microsoft advisory is available at:
http://technet.microsoft.com/en-us/security/bulletin/ms11-100
|
Vendor URL: technet.microsoft.com/en-us/security/bulletin/ms11-100 (Links to External Site)
|
Cause:
Access control error, Authentication error
|
Underlying OS:
Windows (2003), Windows (2008), Windows (7), Windows (Vista), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 29 Dec 2011 21:29:49 +0000
Subject: http://technet.microsoft.com/en-us/security/bulletin/ms11-100
|
Microsoft Security Bulletin MS11-100 - Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420)
CVE-2011-3414
CVE-2011-3415
CVE-2011-3416
CVE-2011-3417
[solution_section]
The vendor has issued the following fixes:
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=7538762a-50e9-4f13-a60e-ff99aa8fbbf8
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=471e1f51-c79c-4285-9f1e-aee1e4c4f189
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=2de28d32-1efd-4177-82e6-19a08266096c
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=26e0b56d-9228-49cf-9276-0741257567a9
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=2de28d32-1efd-4177-82e6-19a08266096c
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=26e0b56d-9228-49cf-9276-0741257567a9
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=2de28d32-1efd-4177-82e6-19a08266096c
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=26e0b56d-9228-49cf-9276-0741257567a9
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=2de28d32-1efd-4177-82e6-19a08266096c
Microsoft .NET Framework 3.5.1:
http://www.microsoft.com/downloads/details.aspx?familyid=26e0b56d-9228-49cf-9276-0741257567a9
The Microsoft advisory is available at:
http://technet.microsoft.com/en-us/security/bulletin/ms11-100
[/solution_section]
[bugno]2638420
[msno]MS11-100
[severity]Critical
|
|