CVE Vulnerabilities

CVE-2011-3417

Published: Dec 30, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka ASP.NET Forms Authentication Ticket Caching Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Windows_7Microsoft- (including)- (including)
Windows_7Microsoft–sp1 (including)–sp1 (including)
Windows_server_2003Microsoft**
Windows_server_2008Microsoft**
Windows_server_2008Microsoft–sp2 (including)–sp2 (including)
Windows_server_2008Microsoftr2 (including)r2 (including)
Windows_vistaMicrosoft**
Windows_vistaMicrosoft–sp2 (including)–sp2 (including)
Windows_xpMicrosoft**
Windows_xpMicrosoftsp3-unknown (including)sp3-unknown (including)

References