Search

Find a vulnerability

Search criteria

    22 vulnerabilities found for ASP.NET Core by Microsoft

    CVE-2020-0603 (GCVE-0-2020-0603)

    Vulnerability from nvd – Published: 2020-01-14 23:11 – Updated: 2024-08-04 06:11
    VLAI
    Summary
    A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Remote Code Execution
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_MISC
    https://access.redhat.com/errata/RHSA-2020:0130 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2020:0134 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 3.0
    Affected: 3.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T06:11:04.603Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603"
              },
              {
                "name": "RHSA-2020:0130",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0130"
              },
              {
                "name": "RHSA-2020:0134",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0134"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "3.0"
                },
                {
                  "status": "affected",
                  "version": "3.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka \u0027ASP.NET Core Remote Code Execution Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Remote Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-16T19:06:09.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603"
            },
            {
              "name": "RHSA-2020:0130",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0130"
            },
            {
              "name": "RHSA-2020:0134",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0134"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2020-0603",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "3.0"
                              },
                              {
                                "version_value": "3.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka \u0027ASP.NET Core Remote Code Execution Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Remote Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603"
                },
                {
                  "name": "RHSA-2020:0130",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0130"
                },
                {
                  "name": "RHSA-2020:0134",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0134"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2020-0603",
        "datePublished": "2020-01-14T23:11:21.000Z",
        "dateReserved": "2019-11-04T00:00:00.000Z",
        "dateUpdated": "2024-08-04T06:11:04.603Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-0602 (GCVE-0-2020-0602)

    Vulnerability from nvd – Published: 2020-01-14 23:11 – Updated: 2024-08-04 06:11
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_MISC
    https://access.redhat.com/errata/RHSA-2020:0130 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2020:0134 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 3.0
    Affected: 3.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T06:11:04.661Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602"
              },
              {
                "name": "RHSA-2020:0130",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0130"
              },
              {
                "name": "RHSA-2020:0134",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0134"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "3.0"
                },
                {
                  "status": "affected",
                  "version": "3.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-16T19:06:08.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602"
            },
            {
              "name": "RHSA-2020:0130",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0130"
            },
            {
              "name": "RHSA-2020:0134",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0134"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2020-0602",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "3.0"
                              },
                              {
                                "version_value": "3.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602"
                },
                {
                  "name": "RHSA-2020:0130",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0130"
                },
                {
                  "name": "RHSA-2020:0134",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0134"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2020-0602",
        "datePublished": "2020-01-14T23:11:20.000Z",
        "dateReserved": "2019-11-04T00:00:00.000Z",
        "dateUpdated": "2024-08-04T06:11:04.661Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-1302 (GCVE-0-2019-1302)

    Vulnerability from nvd – Published: 2019-09-11 21:25 – Updated: 2024-08-04 18:13
    VLAI
    Summary
    An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Elevation of Privilege
    References
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Affected: 3.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:13:30.222Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                },
                {
                  "status": "affected",
                  "version": "3.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka \u0027ASP.NET Core Elevation Of Privilege Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-09-11T21:25:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-1302",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              },
                              {
                                "version_value": "3.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka \u0027ASP.NET Core Elevation Of Privilege Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Elevation of Privilege"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-1302",
        "datePublished": "2019-09-11T21:25:01.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:13:30.222Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-1075 (GCVE-0-2019-1075)

    Vulnerability from nvd – Published: 2019-07-15 18:56 – Updated: 2024-08-04 18:06
    VLAI
    Summary
    A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Spoofing
    References
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:06:31.539Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka \u0027ASP.NET Core Spoofing Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Spoofing",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-07-15T18:56:20.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-1075",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka \u0027ASP.NET Core Spoofing Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Spoofing"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-1075",
        "datePublished": "2019-07-15T18:56:20.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:06:31.539Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0982 (GCVE-0-2019-0982)

    Vulnerability from nvd – Published: 2019-05-16 18:24 – Updated: 2024-08-04 18:06
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:06:31.304Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-05-16T18:24:57.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0982",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0982",
        "datePublished": "2019-05-16T18:24:57.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:06:31.304Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0815 (GCVE-0-2019-0815)

    Vulnerability from nvd – Published: 2019-04-09 20:16 – Updated: 2024-08-04 17:58
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:58:59.256Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815"
              },
              {
                "name": "107701",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/107701"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-04-09T21:06:06.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815"
            },
            {
              "name": "107701",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/107701"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0815",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815"
                },
                {
                  "name": "107701",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/107701"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0815",
        "datePublished": "2019-04-09T20:16:25.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:58:59.256Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0564 (GCVE-0-2019-0564)

    Vulnerability from nvd – Published: 2019-01-08 21:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/106413 vdb-entryx_refsource_BID
    https://access.redhat.com/errata/RHSA-2019:0040 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Date Public
    2019-01-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:27.161Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564"
              },
              {
                "name": "106413",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106413"
              },
              {
                "name": "RHSA-2019:0040",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0040"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            }
          ],
          "datePublic": "2019-01-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-01-09T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564"
            },
            {
              "name": "106413",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106413"
            },
            {
              "name": "RHSA-2019:0040",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0040"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0564",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564"
                },
                {
                  "name": "106413",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106413"
                },
                {
                  "name": "RHSA-2019:0040",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0040"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0564",
        "datePublished": "2019-01-08T21:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:27.161Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0548 (GCVE-0-2019-0548)

    Vulnerability from nvd – Published: 2019-01-08 21:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    URL Tags
    http://www.securityfocus.com/bid/106410 vdb-entryx_refsource_BID
    https://access.redhat.com/errata/RHSA-2019:0040 vendor-advisoryx_refsource_REDHAT
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Date Public
    2019-01-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:27.229Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "106410",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106410"
              },
              {
                "name": "RHSA-2019:0040",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0040"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "datePublic": "2019-01-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-01-09T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "106410",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106410"
            },
            {
              "name": "RHSA-2019:0040",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0040"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0548",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "106410",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106410"
                },
                {
                  "name": "RHSA-2019:0040",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0040"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0548",
        "datePublished": "2019-01-08T21:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:27.229Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8409 (GCVE-0-2018-8409)

    Vulnerability from nvd – Published: 2018-09-13 00:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    Date Public
    2018-09-12 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.419Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "105223",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105223"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "System.IO.Pipelines",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "System.IO.Pipelines"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            },
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            }
          ],
          "datePublic": "2018-09-12T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka \"System.IO.Pipelines Denial of Service.\" This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-09-13T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "105223",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105223"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8409",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "System.IO.Pipelines",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "System.IO.Pipelines"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka \"System.IO.Pipelines Denial of Service.\" This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "105223",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105223"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8409",
        "datePublished": "2018-09-13T00:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.419Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8356 (GCVE-0-2018-8356)

    Vulnerability from nvd – Published: 2018-07-11 00:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/104664 vdb-entryx_refsource_BID
    http://www.securitytracker.com/id/1041257 vdb-entryx_refsource_SECTRACK
    Impacted products
    Vendor Product Version
    Microsoft Microsoft .NET Framework Affected: 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: 3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
    Affected: 3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
    Affected: 3.5 on Windows 10 for 32-bit Systems
    Affected: 3.5 on Windows 10 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1607 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1607 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1703 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1703 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1709 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1709 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1803 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1803 for x64-based Systems
    Affected: 3.5 on Windows 8.1 for 32-bit systems
    Affected: 3.5 on Windows 8.1 for x64-based systems
    Affected: 3.5 on Windows Server 2012
    Affected: 3.5 on Windows Server 2012 (Server Core installation)
    Affected: 3.5 on Windows Server 2012 R2
    Affected: 3.5 on Windows Server 2012 R2 (Server Core installation)
    Affected: 3.5 on Windows Server 2016
    Affected: 3.5 on Windows Server 2016 (Server Core installation)
    Affected: 3.5 on Windows Server, version 1709 (Server Core Installation)
    Affected: 3.5 on Windows Server, version 1803 (Server Core Installation)
    Affected: 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1
    Affected: 3.5.1 on Windows 7 for x64-based Systems Service Pack 1
    Affected: 3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
    Affected: 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: 4.5.2 on Windows 7 for 32-bit Systems Service Pack 1
    Affected: 4.5.2 on Windows 7 for x64-based Systems Service Pack 1
    Affected: 4.5.2 on Windows 8.1 for 32-bit systems
    Affected: 4.5.2 on Windows 8.1 for x64-based systems
    Affected: 4.5.2 on Windows RT 8.1
    Affected: 4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: 4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2
    Affected: 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: 4.5.2 on Windows Server 2012
    Affected: 4.5.2 on Windows Server 2012 (Server Core installation)
    Affected: 4.5.2 on Windows Server 2012 R2
    Affected: 4.5.2 on Windows Server 2012 R2 (Server Core installation)
    Affected: 4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: 4.6 on Windows Server 2008 for x64-based Systems Service Pack 2
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)
    Affected: 4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems
    Affected: 4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for x64-based systems
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows RT 8.1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)
    Affected: 4.7.2 on Windows 10 Version 1803 for 32-bit Systems
    Affected: 4.7.2 on Windows 10 Version 1803 for x64-based Systems
    Affected: 4.7.2 on Windows Server, version 1803 (Server Core Installation)
    Create a notification for this product.
    Microsoft .NET Core Affected: 1.0
    Affected: 1.1
    Affected: 2.0
    Create a notification for this product.
    Microsoft ASP.NET Core Affected: 1.0
    Affected: 1.1
    Affected: 2.0
    Create a notification for this product.
    Microsoft .NET Framework Affected: 4.7.2 Developer Pack
    Create a notification for this product.
    Date Public
    2018-07-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.082Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356"
              },
              {
                "name": "104664",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/104664"
              },
              {
                "name": "1041257",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1041257"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Microsoft .NET Framework",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2016  (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server, version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server, version 1803  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.6 on Windows Server 2008 for x64-based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.7.2 on Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "4.7.2 on Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "4.7.2 on Windows Server, version 1803  (Server Core Installation)"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.0"
                }
              ]
            },
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.0"
                }
              ]
            },
            {
              "product": ".NET Framework",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.7.2 Developer Pack"
                }
              ]
            }
          ],
          "datePublic": "2018-07-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka \".NET Framework Security Feature Bypass Vulnerability.\" This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-07-11T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356"
            },
            {
              "name": "104664",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/104664"
            },
            {
              "name": "1041257",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1041257"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8356",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Microsoft .NET Framework",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                              },
                              {
                                "version_value": "3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              },
                              {
                                "version_value": "3.5 on Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "3.5 on Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012 R2"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2016"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2016  (Server Core installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server, version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server, version 1803  (Server Core Installation)"
                              },
                              {
                                "version_value": "3.5.1 on Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "4.5.2 on Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.5.2 on Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.5.2 on Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "4.5.2 on Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "4.5.2 on Windows RT 8.1"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012 R2"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.6 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation)"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows RT 8.1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "4.7.2 on Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "4.7.2 on Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "4.7.2 on Windows Server, version 1803  (Server Core Installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Framework",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "4.7.2 Developer Pack"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka \".NET Framework Security Feature Bypass Vulnerability.\" This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356"
                },
                {
                  "name": "104664",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/104664"
                },
                {
                  "name": "1041257",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1041257"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8356",
        "datePublished": "2018-07-11T00:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8171 (GCVE-0-2018-8171)

    Vulnerability from nvd – Published: 2018-07-11 00:00 – Updated: 2024-08-05 06:46
    VLAI
    Summary
    A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    URL Tags
    http://www.securitytracker.com/id/1041267 vdb-entryx_refsource_SECTRACK
    http://www.securityfocus.com/bid/104659 vdb-entryx_refsource_BID
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Affected: Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5
    Affected: Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3
    Create a notification for this product.
    Microsoft ASP.NET Core Affected: 1.0
    Affected: 1.1
    Affected: 2.0
    Create a notification for this product.
    Microsoft ASP.NET MVC 5.2 Affected: Microsoft Visual Studio 2013 Update 5
    Affected: Microsoft Visual Studio 2015 Update 3
    Create a notification for this product.
    Date Public
    2018-07-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:46:13.464Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1041267",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1041267"
              },
              {
                "name": "104659",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/104659"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5"
                },
                {
                  "status": "affected",
                  "version": "Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3"
                }
              ]
            },
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.0"
                }
              ]
            },
            {
              "product": "ASP.NET MVC 5.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Microsoft Visual Studio 2013 Update 5"
                },
                {
                  "status": "affected",
                  "version": "Microsoft Visual Studio 2015 Update 3"
                }
              ]
            }
          ],
          "datePublic": "2018-07-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka \"ASP.NET Security Feature Bypass Vulnerability.\" This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-07-11T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "1041267",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1041267"
            },
            {
              "name": "104659",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/104659"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8171",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5"
                              },
                              {
                                "version_value": "Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET MVC 5.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Microsoft Visual Studio 2013 Update 5"
                              },
                              {
                                "version_value": "Microsoft Visual Studio 2015 Update 3"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka \"ASP.NET Security Feature Bypass Vulnerability.\" This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1041267",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1041267"
                },
                {
                  "name": "104659",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/104659"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8171",
        "datePublished": "2018-07-11T00:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:46:13.464Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-0603 (GCVE-0-2020-0603)

    Vulnerability from cvelistv5 – Published: 2020-01-14 23:11 – Updated: 2024-08-04 06:11
    VLAI
    Summary
    A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Remote Code Execution
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_MISC
    https://access.redhat.com/errata/RHSA-2020:0130 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2020:0134 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 3.0
    Affected: 3.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T06:11:04.603Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603"
              },
              {
                "name": "RHSA-2020:0130",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0130"
              },
              {
                "name": "RHSA-2020:0134",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0134"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "3.0"
                },
                {
                  "status": "affected",
                  "version": "3.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka \u0027ASP.NET Core Remote Code Execution Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Remote Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-16T19:06:09.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603"
            },
            {
              "name": "RHSA-2020:0130",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0130"
            },
            {
              "name": "RHSA-2020:0134",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0134"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2020-0603",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "3.0"
                              },
                              {
                                "version_value": "3.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka \u0027ASP.NET Core Remote Code Execution Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Remote Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603"
                },
                {
                  "name": "RHSA-2020:0130",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0130"
                },
                {
                  "name": "RHSA-2020:0134",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0134"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2020-0603",
        "datePublished": "2020-01-14T23:11:21.000Z",
        "dateReserved": "2019-11-04T00:00:00.000Z",
        "dateUpdated": "2024-08-04T06:11:04.603Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-0602 (GCVE-0-2020-0602)

    Vulnerability from cvelistv5 – Published: 2020-01-14 23:11 – Updated: 2024-08-04 06:11
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_MISC
    https://access.redhat.com/errata/RHSA-2020:0130 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2020:0134 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 3.0
    Affected: 3.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T06:11:04.661Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602"
              },
              {
                "name": "RHSA-2020:0130",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0130"
              },
              {
                "name": "RHSA-2020:0134",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0134"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "3.0"
                },
                {
                  "status": "affected",
                  "version": "3.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-16T19:06:08.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602"
            },
            {
              "name": "RHSA-2020:0130",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0130"
            },
            {
              "name": "RHSA-2020:0134",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0134"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2020-0602",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "3.0"
                              },
                              {
                                "version_value": "3.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602"
                },
                {
                  "name": "RHSA-2020:0130",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0130"
                },
                {
                  "name": "RHSA-2020:0134",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0134"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2020-0602",
        "datePublished": "2020-01-14T23:11:20.000Z",
        "dateReserved": "2019-11-04T00:00:00.000Z",
        "dateUpdated": "2024-08-04T06:11:04.661Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-1302 (GCVE-0-2019-1302)

    Vulnerability from cvelistv5 – Published: 2019-09-11 21:25 – Updated: 2024-08-04 18:13
    VLAI
    Summary
    An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Elevation of Privilege
    References
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Affected: 3.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:13:30.222Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                },
                {
                  "status": "affected",
                  "version": "3.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka \u0027ASP.NET Core Elevation Of Privilege Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-09-11T21:25:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-1302",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              },
                              {
                                "version_value": "3.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka \u0027ASP.NET Core Elevation Of Privilege Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Elevation of Privilege"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-1302",
        "datePublished": "2019-09-11T21:25:01.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:13:30.222Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-1075 (GCVE-0-2019-1075)

    Vulnerability from cvelistv5 – Published: 2019-07-15 18:56 – Updated: 2024-08-04 18:06
    VLAI
    Summary
    A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Spoofing
    References
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:06:31.539Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka \u0027ASP.NET Core Spoofing Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Spoofing",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-07-15T18:56:20.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-1075",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka \u0027ASP.NET Core Spoofing Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Spoofing"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1075"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-1075",
        "datePublished": "2019-07-15T18:56:20.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:06:31.539Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0982 (GCVE-0-2019-0982)

    Vulnerability from cvelistv5 – Published: 2019-05-16 18:24 – Updated: 2024-08-04 18:06
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:06:31.304Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-05-16T18:24:57.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0982",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0982"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0982",
        "datePublished": "2019-05-16T18:24:57.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:06:31.304Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0815 (GCVE-0-2019-0815)

    Vulnerability from cvelistv5 – Published: 2019-04-09 20:16 – Updated: 2024-08-04 17:58
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:58:59.256Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815"
              },
              {
                "name": "107701",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/107701"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-04-09T21:06:06.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815"
            },
            {
              "name": "107701",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/107701"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0815",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \u0027ASP.NET Core Denial of Service Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0815"
                },
                {
                  "name": "107701",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/107701"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0815",
        "datePublished": "2019-04-09T20:16:25.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:58:59.256Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0564 (GCVE-0-2019-0564)

    Vulnerability from cvelistv5 – Published: 2019-01-08 21:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/106413 vdb-entryx_refsource_BID
    https://access.redhat.com/errata/RHSA-2019:0040 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Date Public
    2019-01-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:27.161Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564"
              },
              {
                "name": "106413",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106413"
              },
              {
                "name": "RHSA-2019:0040",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0040"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            }
          ],
          "datePublic": "2019-01-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-01-09T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564"
            },
            {
              "name": "106413",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106413"
            },
            {
              "name": "RHSA-2019:0040",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0040"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0564",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0564"
                },
                {
                  "name": "106413",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106413"
                },
                {
                  "name": "RHSA-2019:0040",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0040"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0564",
        "datePublished": "2019-01-08T21:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:27.161Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0548 (GCVE-0-2019-0548)

    Vulnerability from cvelistv5 – Published: 2019-01-08 21:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    URL Tags
    http://www.securityfocus.com/bid/106410 vdb-entryx_refsource_BID
    https://access.redhat.com/errata/RHSA-2019:0040 vendor-advisoryx_refsource_REDHAT
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Core Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Date Public
    2019-01-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:27.229Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "106410",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106410"
              },
              {
                "name": "RHSA-2019:0040",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0040"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            }
          ],
          "datePublic": "2019-01-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-01-09T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "106410",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106410"
            },
            {
              "name": "RHSA-2019:0040",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0040"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0548",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka \"ASP.NET Core Denial of Service Vulnerability.\" This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "106410",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106410"
                },
                {
                  "name": "RHSA-2019:0040",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0040"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0548",
        "datePublished": "2019-01-08T21:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:27.229Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8409 (GCVE-0-2018-8409)

    Vulnerability from cvelistv5 – Published: 2018-09-13 00:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
    Severity
    No CVSS data available.
    CWE
    • Denial of Service
    References
    Date Public
    2018-09-12 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.419Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "105223",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105223"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "System.IO.Pipelines",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "System.IO.Pipelines"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            },
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            }
          ],
          "datePublic": "2018-09-12T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka \"System.IO.Pipelines Denial of Service.\" This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-09-13T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "105223",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105223"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8409",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "System.IO.Pipelines",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "System.IO.Pipelines"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka \"System.IO.Pipelines Denial of Service.\" This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial of Service"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "105223",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105223"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8409",
        "datePublished": "2018-09-13T00:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.419Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8171 (GCVE-0-2018-8171)

    Vulnerability from cvelistv5 – Published: 2018-07-11 00:00 – Updated: 2024-08-05 06:46
    VLAI
    Summary
    A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    URL Tags
    http://www.securitytracker.com/id/1041267 vdb-entryx_refsource_SECTRACK
    http://www.securityfocus.com/bid/104659 vdb-entryx_refsource_BID
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Microsoft ASP.NET Affected: Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5
    Affected: Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3
    Create a notification for this product.
    Microsoft ASP.NET Core Affected: 1.0
    Affected: 1.1
    Affected: 2.0
    Create a notification for this product.
    Microsoft ASP.NET MVC 5.2 Affected: Microsoft Visual Studio 2013 Update 5
    Affected: Microsoft Visual Studio 2015 Update 3
    Create a notification for this product.
    Date Public
    2018-07-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:46:13.464Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1041267",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1041267"
              },
              {
                "name": "104659",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/104659"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ASP.NET",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5"
                },
                {
                  "status": "affected",
                  "version": "Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3"
                }
              ]
            },
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.0"
                }
              ]
            },
            {
              "product": "ASP.NET MVC 5.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Microsoft Visual Studio 2013 Update 5"
                },
                {
                  "status": "affected",
                  "version": "Microsoft Visual Studio 2015 Update 3"
                }
              ]
            }
          ],
          "datePublic": "2018-07-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka \"ASP.NET Security Feature Bypass Vulnerability.\" This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-07-11T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "1041267",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1041267"
            },
            {
              "name": "104659",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/104659"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8171",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "ASP.NET",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5"
                              },
                              {
                                "version_value": "Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET MVC 5.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Microsoft Visual Studio 2013 Update 5"
                              },
                              {
                                "version_value": "Microsoft Visual Studio 2015 Update 3"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka \"ASP.NET Security Feature Bypass Vulnerability.\" This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1041267",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1041267"
                },
                {
                  "name": "104659",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/104659"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8171",
        "datePublished": "2018-07-11T00:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:46:13.464Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8356 (GCVE-0-2018-8356)

    Vulnerability from cvelistv5 – Published: 2018-07-11 00:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    URL Tags
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/104664 vdb-entryx_refsource_BID
    http://www.securitytracker.com/id/1041257 vdb-entryx_refsource_SECTRACK
    Impacted products
    Vendor Product Version
    Microsoft Microsoft .NET Framework Affected: 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: 3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
    Affected: 3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
    Affected: 3.5 on Windows 10 for 32-bit Systems
    Affected: 3.5 on Windows 10 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1607 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1607 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1703 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1703 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1709 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1709 for x64-based Systems
    Affected: 3.5 on Windows 10 Version 1803 for 32-bit Systems
    Affected: 3.5 on Windows 10 Version 1803 for x64-based Systems
    Affected: 3.5 on Windows 8.1 for 32-bit systems
    Affected: 3.5 on Windows 8.1 for x64-based systems
    Affected: 3.5 on Windows Server 2012
    Affected: 3.5 on Windows Server 2012 (Server Core installation)
    Affected: 3.5 on Windows Server 2012 R2
    Affected: 3.5 on Windows Server 2012 R2 (Server Core installation)
    Affected: 3.5 on Windows Server 2016
    Affected: 3.5 on Windows Server 2016 (Server Core installation)
    Affected: 3.5 on Windows Server, version 1709 (Server Core Installation)
    Affected: 3.5 on Windows Server, version 1803 (Server Core Installation)
    Affected: 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1
    Affected: 3.5.1 on Windows 7 for x64-based Systems Service Pack 1
    Affected: 3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
    Affected: 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: 4.5.2 on Windows 7 for 32-bit Systems Service Pack 1
    Affected: 4.5.2 on Windows 7 for x64-based Systems Service Pack 1
    Affected: 4.5.2 on Windows 8.1 for 32-bit systems
    Affected: 4.5.2 on Windows 8.1 for x64-based systems
    Affected: 4.5.2 on Windows RT 8.1
    Affected: 4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: 4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2
    Affected: 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: 4.5.2 on Windows Server 2012
    Affected: 4.5.2 on Windows Server 2012 (Server Core installation)
    Affected: 4.5.2 on Windows Server 2012 R2
    Affected: 4.5.2 on Windows Server 2012 R2 (Server Core installation)
    Affected: 4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: 4.6 on Windows Server 2008 for x64-based Systems Service Pack 2
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
    Affected: 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)
    Affected: 4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems
    Affected: 4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for x64-based systems
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows RT 8.1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2
    Affected: 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)
    Affected: 4.7.2 on Windows 10 Version 1803 for 32-bit Systems
    Affected: 4.7.2 on Windows 10 Version 1803 for x64-based Systems
    Affected: 4.7.2 on Windows Server, version 1803 (Server Core Installation)
    Create a notification for this product.
    Microsoft .NET Core Affected: 1.0
    Affected: 1.1
    Affected: 2.0
    Create a notification for this product.
    Microsoft ASP.NET Core Affected: 1.0
    Affected: 1.1
    Affected: 2.0
    Create a notification for this product.
    Microsoft .NET Framework Affected: 4.7.2 Developer Pack
    Create a notification for this product.
    Date Public
    2018-07-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.082Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356"
              },
              {
                "name": "104664",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/104664"
              },
              {
                "name": "1041257",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1041257"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Microsoft .NET Framework",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server 2016  (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server, version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5 on Windows Server, version 1803  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "4.5.2 on Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.6 on Windows Server 2008 for x64-based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "4.7.2 on Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "4.7.2 on Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "4.7.2 on Windows Server, version 1803  (Server Core Installation)"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.0"
                }
              ]
            },
            {
              "product": "ASP.NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.0"
                }
              ]
            },
            {
              "product": ".NET Framework",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.7.2 Developer Pack"
                }
              ]
            }
          ],
          "datePublic": "2018-07-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka \".NET Framework Security Feature Bypass Vulnerability.\" This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-07-11T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356"
            },
            {
              "name": "104664",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/104664"
            },
            {
              "name": "1041257",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1041257"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8356",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Microsoft .NET Framework",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                              },
                              {
                                "version_value": "3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              },
                              {
                                "version_value": "3.5 on Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "3.5 on Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "3.5 on Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012 R2"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2016"
                              },
                              {
                                "version_value": "3.5 on Windows Server 2016  (Server Core installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server, version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "3.5 on Windows Server, version 1803  (Server Core Installation)"
                              },
                              {
                                "version_value": "3.5.1 on Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "4.5.2 on Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.5.2 on Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.5.2 on Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "4.5.2 on Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "4.5.2 on Windows RT 8.1"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012 R2"
                              },
                              {
                                "version_value": "4.5.2 on Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.6 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016"
                              },
                              {
                                "version_value": "4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation)"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows RT 8.1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2"
                              },
                              {
                                "version_value": "4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "4.7.2 on Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "4.7.2 on Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "4.7.2 on Windows Server, version 1803  (Server Core Installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ASP.NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Framework",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "4.7.2 Developer Pack"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka \".NET Framework Security Feature Bypass Vulnerability.\" This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356"
                },
                {
                  "name": "104664",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/104664"
                },
                {
                  "name": "1041257",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1041257"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8356",
        "datePublished": "2018-07-11T00:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }