CVE-2015-1673: Critical severity Microsoft .NET Framework vulnerability
The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation of Privilege Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1673?
CVE-2015-1673 has been rated as important by Microsoft due to its potential to allow remote code execution.
How do I fix CVE-2015-1673?
To fix CVE-2015-1673, users should apply the latest security updates provided by Microsoft for the affected versions of .NET Framework.
Which versions of .NET Framework are affected by CVE-2015-1673?
CVE-2015-1673 affects .NET Framework versions 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4.0, 4.5, 4.5.1, and 4.5.2.
What types of attacks can CVE-2015-1673 enable?
CVE-2015-1673 can enable user-assisted remote attackers to execute arbitrary code on the target system.
Is there any user action required for CVE-2015-1673 to be exploited?
Yes, CVE-2015-1673 requires user assistance, meaning the targeted user must run a crafted partial-trust application for the exploit to succeed.