#VU2992 Denial of service in Microsoft .NET Framework


Published: 2016-12-28 | Updated: 2017-03-14

Vulnerability identifier: #VU2992

Vulnerability risk: Medium

CVSSv3.1: 6.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2012-0164

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Microsoft .NET Framework
Server applications / Frameworks for developing and running applications

Vendor: Microsoft

Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper comparison of the value of an index within a WPF application in .NET Framework. A remote attacker can send a specially crafted request and cause the application to stop responding until a manual restart.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Mitigation
Install update from vendor's website:

Microsoft .NET Framework 4 when installed on Windows XP Service Pack 3:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows XP Professional x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Server 2003 Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Server 2003 x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Vista Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Vista x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Server 2008 for 32-bit Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Server 2008 for x64-based Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows 7 for 32-bit Systems:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows 7 for 32-bit Systems Service Pack 1:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows 7 for x64-based Systems:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows 7 for x64-based Systems Service Pack 1:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Server 2008 R2 for x64-based Systems:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648
Microsoft .NET Framework 4 when installed on Windows Server 2008 R2 for x64-based Systems Service Pack 1:
https://www.microsoft.com/downloads/details.aspx?familyid=4ee3cb61-542e-4e42-aa0e-0cbf8dd89648

Vulnerable software versions

Microsoft .NET Framework: 4.0


External links
http://technet.microsoft.com/en-us/library/security/ms12-034


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability