CVE-2011-1271
46Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.7epss 20%
from disclosure to weapon0 days
Published on NVDMay 10
1st PoCMar 4
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework JIT Optimization Vulnerability."
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/35740⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.