Uočen je jedan sigurnosni nedostatak u paketu Microsoft .NET Framework, točnije, njegovoj komponenti Microsoft .NET Runtime Optimization Service. Otkriveni nedostatak je posljedica nesigurnog rukovanja ovlastima u "mscorsvw.exe", a mogu ga iskoristiti lokalni napadači kako bi povećali svoje ovlasti na ranjivom sustavu. Uspješni napad može rezultirati izvođenjem proizvoljnog programskog koda sa SYSTEM ovlastima. Za sada ne postoji programska zakrpa kojom bi se otklonio opisani sigurnosni nedostatak.

Microsoft .NET Runtime Optimization Service Local Privilege Escalation

Rated as 	Moderate Risk 
Release Date 	2011-03-08
Technical Description

A vulnerability has been identified in Microsoft Windows, which could be exploited by local attackers to gain elevated privileges. This issue is caused by insecure write permissions being set on the .NET Runtime Optimization Service application "mscorsvw.exe", which could allow a malicious Power or Domain user to overwrite the affected executable file with a malicious binary and execute arbitrary code with SYSTEM privileges.

VUPEN has confirmed the vulnerability on fully updated Microsoft Windows Server 2003 SP2 and Microsoft Windows XP SP3 systems with Microsoft .NET Framework version 2.0.50727.

Affected Products

Microsoft Windows XP Service Pack 3
Microsoft Windows Server 2003 Service Pack 2

Microsoft .NET Framework version 2.0.50727


VUPEN Security is not aware of any vendor-supplied patch.



Public Exploit or PoC 

Vulnerability reported by XenoMuta.


2011-03-08 : Initial release

