Blog
Anand Yadav

Microsoft has released an out-of-band bulletin MS11-100

January 2, 2012
0
Estimated reading time: 3 minutes

Microsoft has released an out-of-band bulletin MS11-100 addressing four vulnerabilities. The bulletin is rated by Microsoft as critical and the vulnerabilities are listed as below:

– Collisions in HashTable May Cause DoS Vulnerability (CVE-2011-3414)
– Insecure Redirect in .NET Form Authentication Vulnerability (CVE-2011-3415)
– ASP.Net Forms Authentication Bypass Vulnerability (CVE-2011-3416)
– ASP.NET Forms Authentication Ticket Caching Vulnerability (CVE-2011-3417)

This security update addresses one publicly and three privately disclosed vulnerabilities in Microsoft .NET framework. The most dangerous of these may lead to elevation of privilege status if a potential attacker sends a maliciously crafted web request to the target. Successfully exploiting this system bug could also lead to execution of arbitrary command via an existing account on the ASP.NET site. To do this, an attacker must be registered to an account on the ASP.NET site and use an existing user credential.

Affected software and version:

Windows XP Service Pack 3 Microsoft .NET Framework 1.1 Service Pack 1
Windows XP Service Pack 3 Microsoft .NET Framework 2.0 Service Pack 2
Windows XP Service Pack 3 Microsoft .NET Framework 3.5 Service Pack 1
Windows XP Service Pack 3 Microsoft .NET Framework 4
Windows XP Professional x64 Edition Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows XP Professional x64 Edition Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows XP Professional x64 Edition Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows XP Professional x64 Edition Service Pack 2 Microsoft .NET Framework 4
Windows Server 2003 Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows Server 2003 Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows Server 2003 Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2003 Service Pack 2 Microsoft .NET Framework 4
Windows Server 2003 x64 Edition Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows Server 2003 x64 Edition Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2003 x64 Edition Service Pack 2 Microsoft .NET Framework 4
Windows Server 2003 with SP2 for Itanium-based Systems Microsoft .NET Framework 1.1 Service Pack 1
Windows Server 2003 with SP2 for Itanium-based Systems Microsoft .NET Framework 2.0 Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2003 with SP2 for Itanium-based Systems Microsoft .NET Framework 4
Windows Vista Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows Vista Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows Vista Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows Vista Service Pack 2 Microsoft .NET Framework 4
Windows Vista x64 Edition Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows Vista x64 Edition Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows Vista x64 Edition Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows Vista x64 Edition Service Pack 2 Microsoft .NET Framework 4
Windows Server 2008 for 32-bit Systems Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2 Microsoft .NET Framework 4
Microsoft .NET Framework 4 Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 4 Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 4 Microsoft .NET Framework 3.5 Service Pack 1
Microsoft .NET Framework 4 Microsoft .NET Framework 4
Windows Server 2008 for Itanium-based Systems Service Pack 2 Microsoft .NET Framework 1.1 Service Pack 1
Windows Server 2008 for Itanium-based Systems Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2 Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2008 for Itanium-based Systems Service Pack 2 Microsoft .NET Framework 4
Windows 7 for 32-bit Systems Microsoft .NET Framework 3.5.1
Windows 7 for 32-bit Systems Microsoft .NET Framework 4
Windows 7 for 32-bit Systems Service Pack 1 Microsoft .NET Framework 3.5 Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1 Microsoft .NET Framework 4
Windows 7 for x64-based Systems Microsoft .NET Framework 3.5 Service Pack 1
Windows 7 for x64-based Systems Microsoft .NET Framework 4
Windows 7 for x64-based Systems Service Pack 1 Microsoft .NET Framework 3.5 Service Pack 1
Windows 7 for x64-based Systems Service Pack 1 Microsoft .NET Framework 4
Windows Server 2008 R2 for x64-based Systems Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2008 R2 for x64-based Systems Microsoft .NET Framework 4
Windows Server 2008 R2 for x64-based Systems Service Pack 1 Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 Microsoft .NET Framework 4
Windows Server 2008 R2 for Itanium-based Systems Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems Microsoft .NET Framework 4
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 Microsoft .NET Framework 3.5 Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 Microsoft .NET Framework 4

For detailed information please go through the following link:
http://technet.microsoft.com/en-us/security/bulletin/ms11-100

Have something to add to this story? Share it in the comments.

No Comments, Be The First!

Your email address will not be published.

CAPTCHA Image