CVE-2013-1336 Information

Description

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2 3.5 3.5.1 4 and 4.5 does not properly check signatures which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity aka \XML Digital Signature Spoofing Vulnerability.\

Reference

http://www.us-cert.gov/ncas/alerts/TA13-134A https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-040 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A16559

Share on: