You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ms13-040
About this tag
MS13-040 is a Microsoft security bulletin from May 2013 addressing vulnerabilities in the .NET Framework. The update resolves one privately reported and one publicly disclosed vulnerability that could allow spoofing if a .NET application processes a specially crafted XML file. An attacker exploiting these vulnerabilities could modify XML file contents without invalidating the file's signature and gain access to endpoint functions as an authenticated user. This bulletin is rated Important and applies to various .NET Framework versions. Users are advised to apply the update to mitigate the risk of spoofing attacks.
Severity Rating: Important
Revision Note: V1.0 (May 14, 2013): Bulletin published.
Summary: This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in the .NET Framework. The more severe of the vulnerabilities could allow...