KLA11011
Security Bypass vulnerability in Microsoft .NET Framework
Обновлено: 26/06/2019
Дата обнаружения
09/05/2017
Уровень угрозы
Warning
Описание

An incomplete validation of certificates was found in Microsoft .NET Framework. By exploiting this vulnerability malicious users can bypass security restrictions. This vulnerability can be exploited remotely via a specially designed certificate, which is marked invalid for a specific use, but still can be used by the component.

Пораженные продукты

Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.6.1
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 4.7

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2017-0248
Оказываемое влияние
?
SB 
[?]
Связанные продукты
Microsoft .NET Framework
CVE-IDS
CVE-2017-02485.0Critical
Microsoft official advisories
Microsoft Security Update Guide
KB list

4016871
4019474
4019473
4019472
4019115
4019109
4019113
4019110
4019114
4019111
4019112
4019108