Welcome to the Virus Encyclopedia of Panda Security.
|worm, Trojan or backdoor. It is an important vulnerability in .NET Framework, which allows tampering in the vulnerable computer.|
.NET Framework is a component of the Windows operating system that enables building and running software applications and web services.
The affected .NET Framework versions are the following:
- .NET Framework 1.0 on Windows XP.
- .NET Framework 1.1 on Windows 2008/Vista/2003/XP/2000.
- .NET Framework 2.0 on Windows 2008/Vista/2003/XP/2000.
- .NET Framework 3.5 on Windows 2008/Vista/2003/XP.
- .NET Framework 3.5.1 on Windows 2008 R2/7.
If exploited successfully, MS10-041 allows an attacking user to bypass a cryptographic signature and tamper with signed XML content without the receiver detecting the changes.
This vulnerability is usually exploited by sending specially crafted XML content to a vulnerable system. Office implements XML signature checking to avoid being exploited by an atacking user.
If you have any of the vulnerable versions of .NET Framework, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.