CVE-2013-1337
published 2013-05-15CVE-2013-1337: Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain…
PriorityP358high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
20.63%
97.2th percentile
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://www.us-cert.gov/ncas/alerts/TA13-134Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-040https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16741http://www.us-cert.gov/ncas/alerts/TA13-134Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-040https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16741
2013-05-15
Published