HTTP: Microsoft .NET Framework WinForms Remote Code Execution

This signature detects attempts to exploit a known vulnerability in Microsoft .NET Framework Windows Form. A successful attack can lead to arbitrary code execution.

Extended Description

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."

References

BugTraq: 57126

CVE: CVE-2013-0002

Short Name
HTTP:STC:DOTNET-WINFORMS-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
.NET CVE-2013-0002 Code Execution Framework Microsoft Remote WinForms bid:57126
Release Date
02/18/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3730
False Positive
Unknown
CVSS Score

9.3

Found a potential security threat?