CVE-2018-8356 Information

Description

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates aka .NET Framework Security Feature Bypass Vulnerability.\ This affects .NET Framework 4.7.2 Microsoft .NET Framework 3.0 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 ASP.NET Core 1.1 Microsoft .NET Framework 4.5.2 ASP.NET Core 2.0 ASP.NET Core 1.0 .NET Core 1.1 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.6/4.6.1/4.6.2 .NET Core 1.0 .NET Core 2.0 Microsoft .NET Framework 4.6 Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 Microsoft .NET Framework 4.7.2.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Reference

http://www.securityfocus.com/bid/104664 http://www.securitytracker.com/id/1041257 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

5.5

Share on: