CVE-2016-0132Improper Input Validation in Microsoft NET Framework

Severity
9.8CRITICALNVD
EPSS
32.6%
top 3.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 9
Latest updateMay 14

Description

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security Feature Bypass."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDmicrosoft/net_framework7 versions+6

🔴Vulnerability Details

2
GHSA
GHSA-8f8h-wpxr-85cv: Microsoft2022-05-14
CVEList
CVE-2016-0132: Microsoft2016-03-09

💬Community

1
Bugzilla
CVE-2016-1551 ntp: ntpd reference clock impersonation2016-04-28
CVE-2016-0132 — Improper Input Validation in Microsoft | cvebase