KLA11011
Security Bypass vulnerability in Microsoft .NET Framework
Updated: 06/26/2019
Detect date
?
05/09/2017
Severity
?
Warning
Description

An incomplete validation of certificates was found in Microsoft .NET Framework. By exploiting this vulnerability malicious users can bypass security restrictions. This vulnerability can be exploited remotely via a specially designed certificate, which is marked invalid for a specific use, but still can be used by the component.

Affected products

Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.6.1
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 4.7

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2017-0248

Impacts
?
SB 
[?]
Related products
Microsoft .NET Framework
CVE-IDS
?
CVE-2017-02485.0Critical
Microsoft official advisories
Microsoft Security Update Guide
KB list

4016871
4019474
4019473
4019472
4019115
4019109
4019113
4019110
4019114
4019111
4019112
4019108