CVE-2012-4776 describes a critical vulnerability in Microsoft .NET Framework versions 2.0 SP2 through 4.5, impacting various Windows operating systems. The flaw lies in the Web Proxy Auto-Discovery (WPAD) functionality, which fails to validate configuration data during proxy setting acquisition. This allows remote attackers to execute arbitrary JavaScript code within XAML browser applications (XBAP) or other .NET Framework applications by providing specially crafted data. With a CVSS score of 9.3, this vulnerability is considered critical, indicating a network-based attack with medium complexity that can lead to complete compromise of confidentiality, integrity, and availability. Its high FAUCET Risk Score of 97/100 further emphasizes its severity. Despite its high severity, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for CVE-2012-4776 are minimal, suggesting it has not garnered significant public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:* | ||
3.5.1CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:4.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.