CVE-2018-0786
published 2018-01-10CVE-2018-0786: Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
3.69%
88.5th percentile
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_core | — | — |
| microsoft | net_core | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | powershell_core | — | — |
| msrc | microsoft_net_framework_2.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.5 | — | — |
| msrc | microsoft_net_framework_3.5.1 | — | — |
| msrc | microsoft_net_framework_4.5.2 | — | — |
| msrc | microsoft_net_framework_4.6 | — | — |
| msrc | microsoft_net_framework_4.6.1 | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7 | — | — |
| msrc | microsoft_net_framework_4.6_4.6.1_4.6.2_4.7 | — | — |
| msrc | microsoft_net_framework_4.7 | — | — |
| msrc | microsoft_net_framework_4.7.1 | — | — |
| msrc | net_core_1.0 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Certificate Validation in Microsoft .NET Framework components
ghsa·2018-10-16
CVE-2018-0786 [HIGH] CWE-295 Improper Certificate Validation in Microsoft .NET Framework components
Improper Certificate Validation in Microsoft .NET Framework components
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
OSV
Improper Certificate Validation in Microsoft .NET Framework components
osv·2018-10-16
CVE-2018-0786 [HIGH] Improper Certificate Validation in Microsoft .NET Framework components
Improper Certificate Validation in Microsoft .NET Framework components
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Microsoft
.NET Security Feature Bypass Vulnerability
vendor_msrc·2018-01-09·CVSS 7.5
CVE-2018-0786 [HIGH] .NET Security Feature Bypass Vulnerability
.NET Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Microsoft .NET Framework (and .NET Core) components do not completely validate certificates.
An attacker could present a certificate that is marked invalid for a specific use, but the component uses it for that purpose. This action disregards the Enhanced Key Usage taggings.
The security update addresses the vulnerability by helping to ensure that .NET Framework (and .NET Core) components completely validate certificates.
.NET Framework: .NET Framework
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:Exploitation Unlikely
Remediation: Commit
Reference: https://github.com/dotne
Red Hat
ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
vendor_redhat·2018-01-08·CVSS 7.5
CVE-2018-0786 [HIGH] CWE-295 ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Package: rh-dotnetcore10-dotnetcore (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore11-dotnetcore (.NET Core 1.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet20-dotnet (.NET Core 2.0 on Red Hat Enterprise Linux) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-0786 ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
bugzilla·2018-01-12·CVSS 7.5
CVE-2018-0786 [HIGH] CVE-2018-0786 ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
CVE-2018-0786 ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
.NET Core 1.0, 1.1 and 2.0 do not correctly validate X509 certificates and can allow an attacker to bypass security checks by presenting an invalid certificate marked for a specific use.
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-0786
https://github.com/dotnet/announcements/issues/51
Discussion:
Changed the affects, this is an ASP.Net issue only.
Talos
Microsoft Patch Tuesday - January 2018
blogs_talos·2018-01-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2018
## Microsoft Patch Tuesday - January 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 56 new vulnerabilities with 16 of them rated critical, 39 of them rated important and 1 of them rated Moderate. These vulnerabilities impact ASP.NET, Edge, Internet Explorer, Office, Windows, and more.
In addition to the 56 vulnerabilities addressed, Microsoft has also released an update that addresses Meltdown and Spectre. Mitigations for these two vulnerabilities were published for Windows in ADV180002 . Note that due to incompatibilities with anti-virus products, users and organizations may not have received this update yet. For more information, users shoul
Talos
Microsoft Patch Tuesday - January 2018
blogs_talos·2018-01-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 56 new vulnerabilities with 16 of them rated critical, 39 of them rated important and 1 of them rated Moderate. These vulnerabilities impact ASP.NET, Edge, Internet Explorer, Office, Windows, and more.
In addition to the 56 vulnerabilities addressed, Microsoft has also released an update that addresses Meltdown and Spectre. Mitigations for these two vulnerabilities were published for Windows in ADV180002. Note that due to incompatibilities with anti-virus products, users and organizations may not have received this update yet. For more information, users should refer to Microsoft's knowledge base articl
http://www.securityfocus.com/bid/102380http://www.securitytracker.com/id/1040152https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0786http://www.securityfocus.com/bid/102380http://www.securitytracker.com/id/1040152https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0786
2018-01-10
Published