MS07-040 - remote code execution in .NET Framework?

MS07-040 - remote code execution in .NET Framework?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
MS07-040 - remote code execution in .NET Framework? Sebastian G. 07-10-2007
Posted by Sebastian G. on July 10, 2007, 7:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Can anyone explain how the issues

.NET PE Loader Vulnerability - CVE-2007-0041
.NET JIT Compiler Vulnerability - CVE-2007-0043

could affect a system? According to the description, it allows an attacker
to execute arbitrary code withing the context of the current user. As by
what the PE Loader and the JIT Compiler do, it seems like it would require
the user to execute the malicious program.

I wonder how this should be a security vulnerability since every .NET
program it free to do whatever it wants. Code Access Security is designed to
only help legitimate programs limiting their impact on the system but not to
provide any kind of sandbox, and especially .NET 1.x (listed as affected) is
impossible to redesign for providing any kind of sandboxing.

Alternately: Do you know where and how to contact any representative of the
Microsoft Security Team that could explain the issue?

Similar ThreadsPosted
Microsoft IIS ASP Remote Code Execution Vulnerability July 18, 2006, 10:03 pm
SSRT4788 rev. 0 HP-UX Apache Remote arbitary code execution August 9, 2004, 12:30 pm
SSRT4788 rev. 1 HP-UX Apache Remote arbitrary code execution August 13, 2004, 11:46 am
SSRT4777 rev. 0 HP-UX Apache, PHP remote code execution, Denial of Service August 5, 2004, 2:06 pm
SSRT4777 rev. 1 HP-UX Apache, PHP remote code execution, Denial of Service August 13, 2004, 11:45 am
SSRT051040 rev.0 - HP-UX Mozilla Remote Unauthorized Execution of Privileged Code October 4, 2005, 9:59 pm
HPSBUX02196 SSRT071318 rev.2 - HP-UX Java (JRE and JDK) Remote Execution of Arbitrary Code March 12, 2007, 10:18 am
HPSBUX02108 SSRT061133 rev.6 - HP-UX running Sendmail, Remote Execution of Arbitrary Code April 13, 2006, 8:10 am
HPSBUX02108 SSRT061133 rev.1 - HP-UX running Sendmail, Remote Execution of Arbitrary Code March 30, 2006, 2:14 pm
HPSBUX02108 SSRT061133 rev.2 - HP-UX running Sendmail, Remote Execution of Arbitrary Code March 31, 2006, 10:10 am

The site map in XML format XML site map

Contact Us | Privacy Policy