CVE-2018-0765XML External Entity (XXE) Injection in Microsoft NET Core

Severity
7.5HIGHNVD
EPSS
9.9%
top 6.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateOct 16

Description

A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDmicrosoft/net_framework11 versions+10

Patches

🔴Vulnerability Details

4
OSV
Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents2018-10-16
GHSA
Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents2018-10-16
GHSA
Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents2018-10-16
CVEList
CVE-2018-0765: A denial of service vulnerability exists when2018-05-09

📋Vendor Advisories

3
Red Hat
dotnet: Improper processing of XML documents can allow a remote attacker to cause a denial of service2018-05-08
Microsoft
.NET and .NET Core Denial of Service Vulnerability2018-05-08
Red Hat
Core: Improper processing of XML documents can cause a denial of service2017-11-17

💬Community

1
Bugzilla
CVE-2018-0765 dotnet: Improper processing of XML documents can allow a remote attacker to cause a denial of service2018-05-10
CVE-2018-0765 — XML External Entity (XXE) Injection | cvebase