CVE-2017-8585Improper Input Validation in Microsoft NET Framework

Severity
7.5HIGHNVD
EPSS
27.1%
top 3.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11
Latest updateMay 17

Description

Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDmicrosoft/net_framework4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
Improper Input Validation in Microsoft.NETCore.App2022-05-17
OSV
Improper Input Validation in Microsoft.NETCore.App2022-05-17
CVEList
CVE-2017-8585: Microsoft2017-07-11

📋Vendor Advisories

2
Red Hat
Core: DoS via invalid culture2017-11-14
Microsoft
.NET Denial of Service Vulnerability2017-07-11

💬Community

1
Bugzilla
CVE-2017-8585 .NET Core: DoS via invalid culture2017-11-14
CVE-2017-8585 — Improper Input Validation in Microsoft | cvebase