CVE-2017-0248
published 2017-05-12CVE-2017-0248: Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
5.51%
91.9th percentile
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.aspnetcore.mvc.abstractions | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.abstractions | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.apiexplorer | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.apiexplorer | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.cors | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.cors | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.dataannotations | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.dataannotations | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.formatters.json | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.formatters.json | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.formatters.xml | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.formatters.xml | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.localization | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.localization | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.razor | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.razor | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.razor.host | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.razor.host | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.taghelpers | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.taghelpers | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.viewfeatures | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.viewfeatures | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | microsoft.aspnetcore.mvc.webapicompatshim | >= 1.0.0 < 1.0.4 | 1.0.4 |
| microsoft | microsoft.aspnetcore.mvc.webapicompatshim | >= 1.1.0 < 1.1.3 | 1.1.3 |
| microsoft | net_framework | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
ghsa·2018-10-16
CVE-2017-0248 [MEDIUM] CWE-295 Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
OSV
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
osv·2018-10-16
CVE-2017-0248 [MEDIUM] Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
Microsoft
.NET Security Feature Bypass Vulnerability
vendor_msrc·2017-05-09·CVSS 7.5
CVE-2017-0248 [HIGH] .NET Security Feature Bypass Vulnerability
.NET Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Microsoft .NET Framework (and .NET Core) components do not completely validate certificates.
An attacker could present a certificate that is marked invalid for a specific use, but the component uses it for that purpose. This action disregards the Enhanced Key Usage taggings.
The security update addresses the vulnerability by helping to ensure that .NET Framework (and .NET Core) components completely validate certificates.
FAQ: How do I determine which version of Microsoft .NET Framework is installed on my system?
You can install and run multiple versions of .NET Framework on a system, and you can install the versions in any order. For more information, see Microsoft Knowledge Base
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - May 2017
blogs_talos·2017-05-10·CVSS 7.5
CVE-2017-0290 [HIGH] Microsoft Patch Tuesday - May 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 56 vulnerabilities with 15 of them rated critical and 41 rated important. Impacted products include .NET, DirectX, Edge, Internet Explorer, Office, Sharepoint, and Windows.
In addition to the coverage Talos is providing for the normal monthly Microsoft security advisories, Talos is also providing coverage for CVE-2017-0290, the MsMpEng Malware Protection service vulnerability in Windows reported by Natalie Silvanovich and Tavis Ormandy of Google Project Zero. Snort rule SIDs for this specific vulnerability are 42820-42821.
## Vulnerabilities Rated Critical The following vulnerabilities are rated critical by Microsoft:
- CVE-2017-0221
- CVE-2017-0222
- CV
Bugzilla
CVE-2016-6344 JBoss bpms 6.3.x cookie does not set httponly
bugzilla·2016-08-31·CVSS 5.3
CVE-2016-6344 [MEDIUM] CVE-2016-6344 JBoss bpms 6.3.x cookie does not set httponly
CVE-2016-6344 JBoss bpms 6.3.x cookie does not set httponly
Cookies including JSESSIONID does not set httponly, so attackers may be able to access information which needs authentication using them.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat Product Security Team)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.1
Via RHSA-2017:0249 https://rhn.redhat.com/errata/RHSA-2017-0249.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.1
Via RHSA-2017:0248 https://rhn.redhat.com/errata/RHSA-2017-0248.html
Bugzilla
CVE-2016-4434 tika: XML External Entity vulnerability
bugzilla·2016-05-27·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434 tika: XML External Entity vulnerability
CVE-2016-4434 tika: XML External Entity vulnerability
Apache Tika parses XML within numerous file formats. In some instances, such as spreadsheets in OOXML files, XMP in PDF, and other file formats, the initialization of the XML parser or the choice of handlers did not protect against XML External Entity (XXE) vulnerabilities.
References:
http://seclists.org/oss-sec/2016/q2/413
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1340387]
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.1
Via RHSA-2017:0249 https://rhn.redhat.com/errata/RHSA-2017-0249.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.1
Via RHSA-2017:0248 https://rhn.redhat.com/errata/RHSA-2017-0248.html
http://www.securityfocus.com/bid/98117http://www.securitytracker.com/id/1038458https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0248http://www.securityfocus.com/bid/98117http://www.securitytracker.com/id/1038458https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0248
2017-05-12
Published