CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2010-1898

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1910%
EPSS Percentile7.50th
Published2010年8月11日
Last Modified2026年4月29日

Vulnerability Description

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."

Affected Platforms (CPE)

📦
Microsoft

.net Framework

= 2.0
📦
Microsoft

.net Framework

= 2.0
📦
Microsoft

.net Framework

= 3.5
📦
Microsoft

.net Framework

= 3.5
📦
Microsoft

.net Framework

= 3.5.1
📦
Microsoft

Silverlight

<= 3.0.40818.0
📦
Microsoft

Silverlight

= 2.0.31005.00
📦
Microsoft

Silverlight

= 2.0.40115.00
📦
Microsoft

Silverlight

= 3.0.40624.00
📦
Microsoft

Silverlight

= 3.0.40723.0
📦
Microsoft

Silverlight

<= 3.0.50106.0
📦
Microsoft

Silverlight

= 3.0.40818.0

References & Advisories

相關漏洞威脅