KLA11248
Multiple vulnerabilities in Microsoft Developer Tools

Обновлено: 22/07/2020
Дата обнаружения
08/05/2018
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to spoof user interface, bypass security restrictions, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A spoofing vulnerability in Azure IoT SDK can be exploited remotely to spoof user interface.
  2. A security feature bypass vulnerability in .NET Framework Device Guard can be exploited remotely to bypass security restrictions.
  3. A denial of service vulnerability in .NET and .NET Core can be exploited remotely via specially crafted requests to cause denial of service.
Пораженные продукты

Microsoft .NET Framework 4.7.2
.NET Core 2.0
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.7.1
C# SDK for Azure IoT
Microsoft .NET Framework 4.6.2/4.7/4.7.1
Microsoft .NET Framework 4.6/4.6.1/4.6.2
Java SDK for Azure IoT
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1
Microsoft .NET Framework 4.7/4.7.1
C SDK for Azure IoT

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2018-8119
CVE-2018-1039
CVE-2018-0765
Оказываемое влияние
?
DoS 
[?]

SB 
[?]

SUI 
[?]
Связанные продукты
Microsoft .NET Framework
Microsoft Azure
CVE-IDS
CVE-2018-07655.0Critical
CVE-2018-10394.6Warning
CVE-2018-81196.8High