Security Feature Bypass in Microsoft .NET Framework and PowerShell Core
CVE-2018-0786
7.5HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 January 2018
Summary
A security feature bypass vulnerability exists in the way Microsoft .NET Framework and PowerShell Core validate certificates. This flaw can potentially allow attackers to bypass security measures, leading to unauthorized access or manipulation of sensitive data. The affected versions include several iterations of both the .NET Framework and PowerShell Core, necessitating prompt attention from system administrators and developers to mitigate the risks associated with this vulnerability.
Affected Version(s)
.NET Framework, .NET Core, and PowerShell Core Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, PowerShell Core 6.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved