cbcvebase.
CVE-2017-8585
published 2017-07-11

CVE-2017-8585: Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of…

PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
9.50%
94.9th percentile
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
msrcmicrosoft_net_framework_4.6.1_on_windows_10_version_1511_for_32-bit_systems
msrcmicrosoft_net_framework_4.6.1_on_windows_10_version_1511_for_x64-based_systems
msrcmicrosoft_net_framework_4.6.2_4.7_on_windows_10_version_1607_for_32-bit_systems
msrcmicrosoft_net_framework_4.6.2_4.7_on_windows_10_version_1607_for_x64-based_syst
msrcmicrosoft_net_framework_4.6.2_4.7_on_windows_server_2016
msrcmicrosoft_net_framework_4.6_on_windows_10_for_32-bit_systems
msrcmicrosoft_net_framework_4.6_on_windows_10_for_x64-based_systems
msrcmicrosoft_net_framework_4.7_on_windows_10_version_1703_for_32-bit_systems
msrcmicrosoft_net_framework_4.7_on_windows_10_version_1703_for_x64-based_systems
msrcnet_core_1.0
msrcnet_core_1.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.