CVE-2009-0091

Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
microsoftCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
microsoftwindows_2000
*
microsoft.net_framework
1.1:sp1
microsoft.net_framework
2.0:sp1
microsoft.net_framework
2.0:sp2
microsoftwindows_server_2003
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoft.net_framework
1.1:sp1
microsoft.net_framework
2.0:sp1
microsoft.net_framework
2.0:sp2
microsoft.net_framework
3.5
microsoft.net_framework
3.5:sp1
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoft.net_framework
1.1:sp1
microsoft.net_framework
2.0
microsoft.net_framework
2.0:sp1
microsoft.net_framework
2.0:sp2
microsoft.net_framework
3.5
microsoft.net_framework
3.5:sp1
microsoft.net_framework
1.1:sp1
microsoftwindows_7
-
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoft.net_framework
1.0:sp3
microsoft.net_framework
1.1:sp1
microsoft.net_framework
2.0:sp1
microsoft.net_framework
2.0:sp2
microsoft.net_framework
3.5
microsoft.net_framework
3.5:sp1
microsoftwindows_xp
*
microsoftwindows_xp
*
microsoftwindows_xp
-
𝑥
= Vulnerable software versions