KLA10802
Information disclosure vulnerability in Microsoft .NET Framework
Updated: 06/01/2019
Detect date
?
05/10/2016
Severity
?
Warning
Description

An unspecified vulnerability was found in Microsoft .NET Framework. By exploiting this vulnerability malicious users can decrypt SSL/TLS traffic. This vulnerability can be exploited remotely via a man-in-the-middle attack.


Technical details

First of all users with TLS 1.2 enabled aren’t affected. To exploit this vulnerability attacker would first inject unencrypted data into the secure channel and then perform MiTM attack. Microsoft recommends to download and test update in controlledmanaged environments before deploying it in production environment. In case of compatibility issues this vulnerability can be mitigated via checking that server and client endpoints correctly implementing TLS RFC. For further instructions you can look at Microsoft KB3155464, listed at solution section.

Affected products

Microsoft .NET Framework versions 2.0 Service Pack 2, 3.5, 3.5.1, 4.5.2, 4.6/4.6.1

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)
KB3155464

Original advisories

CVE-2016-0149

Impacts
?
OSI 
[?]
Related products
Microsoft .NET Framework
CVE-IDS
?
CVE-2016-01494.3Warning
Microsoft official advisories
Microsoft Security Update Guide
KB list

3156421
3156387
3142023
3142024
3142025
3142026
3142037
3142036
3142035
3142033
3142032
3142030
3156757