cbcvebase.
CVE-2013-0005
published 2013-01-09

CVE-2013-0005: The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData…

PriorityP344high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
32.10%
98.1th percentile
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Target the WCF Replace function in the OData protocol implementation — look for crafted HTTP requests containing anomalous values passed to the Replace function that could cause resource exhaustion.
  • Monitor IIS/WCF OData endpoints for abnormal resource consumption or unexpected service/daemon restarts, which are indicators of exploitation of this DoS vulnerability.
  • ·Vulnerability affects multiple versions of .NET Framework (3.5, 3.5 SP1, 3.5.1, 4) and the Management OData IIS Extension on Windows Server 2012; detection scope should cover all affected platforms.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.