KLA10786
Code execution vulnerabilities in Microsoft Developer Tools
Обновлено: 22/07/2020
Дата обнаружения
12/04/2016
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in .NET Framework can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in GDI+ can be exploited remotely via specially crafted embedded to execute arbitrary code.
Пораженные продукты

Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.6/4.6.1

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2016-0148
CVE-2016-0145
Оказываемое влияние
?
ACE 
[?]
Связанные продукты
Microsoft .NET Framework
CVE-IDS
CVE-2016-01480.0Unknown
CVE-2016-01450.0Unknown
Microsoft official advisories
Microsoft Security Update Guide
KB list

3147461
3147458
3143693
3142045
3142042
3142043
3142041

Эксплуатация

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/39743

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.