KLA11011
Security Bypass vulnerability in Microsoft .NET Framework
Updated: 05/22/2017
CVSS
?
0.0
Detect date
?
05/08/2017
Severity
?
Warning
Description

An incomplete validation of certificates was found in Microsoft .NET Framework. By exploiting this vulnerability malicious users can bypass security restrictions. This vulnerability can be exploited remotely via a specially designed certificate, which is marked invalid for a specific use, but still can be used by the component.

NB: This vulnerability doesn’t have a public CVSS rating so rating can be changed by the time.

Affected products

Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.6.1
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 4.7
 

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2017-0248

Impacts
?
SB 
[?]
Related products
Microsoft .NET Framework
CVE-IDS
?

CVE-2017-0248

MS list
CVE-2017-0248
KB list

4019115
4019109
4019474
4016871
4019113
4019110
4019473
4019114
4019111
4019472
4019112
4019108
4019109
4019108
4019114