CVE-2017-8585
published 2017-07-11CVE-2017-8585: Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
9.50%
94.9th percentile
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| msrc | microsoft_net_framework_4.6.1_on_windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | microsoft_net_framework_4.6.1_on_windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7_on_windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7_on_windows_10_version_1607_for_x64-based_syst | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7_on_windows_server_2016 | — | — |
| msrc | microsoft_net_framework_4.6_on_windows_10_for_32-bit_systems | — | — |
| msrc | microsoft_net_framework_4.6_on_windows_10_for_x64-based_systems | — | — |
| msrc | microsoft_net_framework_4.7_on_windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | microsoft_net_framework_4.7_on_windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | net_core_1.0 | — | — |
| msrc | net_core_1.1 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Input Validation in Microsoft.NETCore.App
ghsa·2022-05-17
CVE-2017-8585 [HIGH] CWE-20 Improper Input Validation in Microsoft.NETCore.App
Improper Input Validation in Microsoft.NETCore.App
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
OSV
Improper Input Validation in Microsoft.NETCore.App
osv·2022-05-17
CVE-2017-8585 [HIGH] Improper Input Validation in Microsoft.NETCore.App
Improper Input Validation in Microsoft.NETCore.App
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
Red Hat
Core: DoS via invalid culture
vendor_redhat·2017-11-14·CVSS 7.5
CVE-2017-8585 [HIGH] Core: DoS via invalid culture
Core: DoS via invalid culture
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
Microsoft
.NET Denial of Service Vulnerability
vendor_msrc·2017-07-11·CVSS 7.5
CVE-2017-8585 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET web application.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET application.
The update addresses the vulnerability by correcting how the .NET web application handles web requests.
.NET Framework: .NET Framework
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:Exploitation Unlikely
Remediation: Commit
Reference: https://github.com/dotnet/core/blob/mas
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-8585 .NET Core: DoS via invalid culture
bugzilla·2017-11-14·CVSS 7.5
CVE-2017-8585 [HIGH] CVE-2017-8585 .NET Core: DoS via invalid culture
CVE-2017-8585 .NET Core: DoS via invalid culture
By providing an invalid culture, an attacker can cause a recursive lookup that leads to a denial of service.
Discussion:
The upstream note about this CVE (https://github.com/dotnet/announcements/issues/34) states:
"""
System administrators are advised to update their .NET Core runtimes to versions 1.0.7 and 1.1.4.
"""
It looks like this was fixed even before .NET Core 1.1.5 and 1.0.8.
The announcement also states:
"""
.NET Core 1.x applications are only affected if running on Windows 10 or Windows 2016.
"""
This doesnt appear to affect Linux. But due to how self-contained applications can be built for other platforms, this needs to be fixed everywhere.
---
This issue has been addressed in the following products:
dotNET on RHEL
Vi
Talos
Microsoft Patch Tuesday - July 2017
blogs_talos·2017-07-11·CVSS 7.8
CVE-2017-8463 [HIGH] Microsoft Patch Tuesday - July 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 54 vulnerabilities with 19 of them rated critical, 32 rated important, and 3 rated moderate. Impacted products include Edge, .NET Framework, Internet Explorer, Office, and Windows.
### Vulnerabilities Rated Critical
#### CVE-2017-8463
This is a remote code execution vulnerability related to the way that Windows Explorer handles executable files and shares during rename operations. If exploited this vulnerability could run arbitrary code, users not running as administrators would be less affected. This vulnerability can be triggered via a malicious share folder and malware named with an executable extension.
#### CVE-2017-8584 A remote code execution vul
http://www.securityfocus.com/bid/99432http://www.securitytracker.com/id/1038864https://access.redhat.com/errata/RHSA-2017:3248https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8585http://www.securityfocus.com/bid/99432http://www.securitytracker.com/id/1038864https://access.redhat.com/errata/RHSA-2017:3248https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8585
2017-07-11
Published