Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2017-0248

Опубликовано: 09 мая 2017
Источник: msrc
EPSS Низкий

Описание

.NET Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Microsoft .NET Framework (and .NET Core) components do not completely validate certificates.

An attacker could present a certificate that is marked invalid for a specific use, but the component uses it for that purpose. This action disregards the Enhanced Key Usage taggings.

The security update addresses the vulnerability by helping to ensure that .NET Framework (and .NET Core) components completely validate certificates.

FAQ

How do I determine which version of Microsoft .NET Framework is installed on my system? You can install and run multiple versions of .NET Framework on a system, and you can install the versions in any order. For more information, see Microsoft Knowledge Base Article 318785.

How do I locate the updates for the versions of .NET Framework installed on my system? The download links in the Affected Products table are to the Parent KB number in the Microsoft Update Catalog. To locate the packages you need to download, in the Microsoft Update Catalog, click Download for the platform you have installed on your system. In the Download window, click to download each update that is applicable to your system.

Customers who have updates automatically installed will be offered the Parent KB; however, the package KB numbers listed for each platform will be displayed in Add Remove Programs.

The following table lists the Parent KB numbers for the Monthly Rollup Releases and the Security Only Releases, and the package KB numbers they contain. For more information about Microsoft's update servicing model for Microsoft .NET Framework, see this Microsoft .NET Blog Post.

Monthly Rollup ReleaseSecurity Only Release
PlatformParent KBChild KBsParent KBChild KBs
Windows Server 200840191154014502 - .NET Framework 2.040191094014575 - .NET Framework 2.0
4014514 - .NET Framework 4.5.24014599 - .NET Framework 4.5.2
4014511 - .NET Framework 4.64014591- .NET Framework 4.6
Windows 740191124014504 - .NET Framework 3.5.140191084014579 - .NET Framework 3.5.1
Windows Server 2008 R24014514 - .NET Framework 4.5.24014599 - .NET Framework 4.5.2
4014511 - .NET Framework 4.6/4.6.14014591 - .NET Framework 4.6/4.6.1
4014508 - .NET Framework 4.6.24014588 - .NET Framework 4.6.2
Windows Server 201240191134014503 - .NET Framework 3.540191104014577 - .NET Framework 3.5
4014513 - .NET Framework 4.5.24014597 - .NET Framework 4.5.2
4014509 - .NET Framework 4.6/4.6.14014589 - .NET Framework 4.6/4.6.1
4014506 - .NET Framework 4.6.24014586 - .NET Framework 4.6.2
Windows 8.140191144014505 - .NET Framework 3.540191114014581 - .NET Framework 3.5
Windows Server 2012 R24014512 - .NET Framework 4.5.24014595 - .NET Framework 4.5.2
4014510 - .NET Framework 4.6/4.6.14014590 - .NET Framework 4.6/4.6.1
4014507 - .NET Framework 4.6.24014587 - .NET Framework 4.6.2
Windows 10 PlatformsParent KB.NET Framework Product
Windows 104019474.NET Framework 3.5None
.NET Framework 4.6
Windows 10 Version 15114019473.NET Framework 3.5None
.NET Framework 4.6.1
Windows 10 Version 16074019472.NET Framework 3.5None
.NET Framework 4.6.2
Windows Server 20164019472.NET Framework 3.5None
.NET Framework 4.6.2
Windows 10 Version 17034019471.NET Framework 4.7None

Обновления

ПродуктСтатьяОбновление
Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)
Microsoft .NET Framework 3.5 on Windows Server 2012
Microsoft .NET Framework 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Microsoft .NET Framework 3.5.1 on Windows 7 for x64-based Systems Service Pack 1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

Older Software Release

Exploitation Unlikely

DOS

N/A

EPSS

Процентиль: 77%
0.01092
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 8 лет назад

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

github
больше 6 лет назад

Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core

EPSS

Процентиль: 77%
0.01092
Низкий