CVE-2017-11770
published 2017-11-15CVE-2017-11770: .NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
5.42%
91.8th percentile
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | aspnetcore | — | — |
| microsoft | aspnetcore | — | — |
| microsoft | aspnetcore | — | — |
| microsoft_corporation | net_core | — | — |
| msrc | net_core_1.0 | — | — |
| msrc | net_core_1.1 | — | — |
| msrc | net_core_2.0 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Certificate Validation
ghsa·2022-04-12
CVE-2017-11770 [HIGH] CWE-295 Improper Certificate Validation
Improper Certificate Validation
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
OSV
Improper Certificate Validation
osv·2022-04-12
CVE-2017-11770 [HIGH] Improper Certificate Validation
Improper Certificate Validation
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
Red Hat
Core: DoS via bad certificate
vendor_redhat·2017-11-14·CVSS 7.5
CVE-2017-11770 [HIGH] Core: DoS via bad certificate
Core: DoS via bad certificate
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
Microsoft
.NET CORE Denial Of Service Vulnerability
vendor_msrc·2017-11-14·CVSS 7.5
CVE-2017-11770 [HIGH] .NET CORE Denial Of Service Vulnerability
.NET CORE Denial Of Service Vulnerability
Description: A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core web application.
The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by providing a specially crafted certificate to the .NET Core application.
The update addresses the vulnerability by correcting how the .NET Core web application handles parsing certificate data.
.NET Framework: .NET Framework
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:Expl
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11770 .NET Core: DoS via bad certificate
bugzilla·2017-11-14·CVSS 7.5
CVE-2017-11770 [HIGH] CVE-2017-11770 .NET Core: DoS via bad certificate
CVE-2017-11770 .NET Core: DoS via bad certificate
Supplying a specially crafted certificate can cause an infinite X509Chain, resulting in a denial of service.
Discussion:
This issue has been addressed in the following products:
dotNET on RHEL
Via RHSA-2017:3248 https://access.redhat.com/errata/RHSA-2017:3248
---
Further details of this issue can be found in the upstream Microsoft advisories:
https://github.com/dotnet/announcements/issues/44
https://github.com/dotnet/corefx/issues/25245
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11770
---
External References:
https://github.com/dotnet/announcements/issues/44
Talos
Microsoft Patch Tuesday - November 2017
blogs_talos·2017-11-14·CVSS 7.5
CVE-2017-16367 [HIGH] Microsoft Patch Tuesday - November 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 53 new vulnerabilities with 19 of them rated critical, 31 of them rated important and 3 of them rated moderate. These vulnerabilities impact Microsoft Edge, Internet Explorer, Microsoft Scripting Engine, and more.
In addition, an update for Adobe Reader was released which addresses CVE-2017-16367 / TALOS-2017-0356 - Adobe Acrobat Reader DC PDF Structured Hierarchy ActualText Structure Element Code Execution Vulnerability which was discovered by Aleksandar Nikolic of Cisco Talos. This vulnerability manifests as a type confusion vulnerability in the PDF parsing functionality for documents containing marked stru
http://www.securityfocus.com/bid/101710http://www.securitytracker.com/id/1039787https://access.redhat.com/errata/RHSA-2017:3248https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11770http://www.securityfocus.com/bid/101710http://www.securitytracker.com/id/1039787https://access.redhat.com/errata/RHSA-2017:3248https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11770
2017-11-15
Published