Searching
..

Click anywhere to stop

KLA11011
Security Bypass vulnerability in Microsoft .NET Framework

Обновлено: 22/01/2024
Дата обнаружения
09/05/2017
Уровень угрозы
Warning
Описание

An incomplete validation of certificates was found in Microsoft .NET Framework. By exploiting this vulnerability malicious users can bypass security restrictions. This vulnerability can be exploited remotely via a specially designed certificate, which is marked invalid for a specific use, but still can be used by the component.

Пораженные продукты

Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.6.1
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 4.7

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2017-0248
Оказываемое влияние
?
SB 
[?]
Связанные продукты
Microsoft .NET Framework
CVE-IDS
CVE-2017-02485.0Warning