CVE-2018-0808
published 2018-03-14CVE-2018-0808: ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
8.07%
94.1th percentile
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft_corporation | asp.net_core | — | — |
| msrc | asp.net_core_2.0 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5cxg-gwxr-pcmf: ASP
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2018-0784 [HIGH] GHSA-5cxg-gwxr-pcmf: ASP
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.
GHSA
GHSA-4f6j-pw77-g8r4: ASP
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-0808 [HIGH] GHSA-4f6j-pw77-g8r4: ASP
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.
Microsoft
ASP.NET Core Denial of Service Vulnerability
vendor_msrc·2018-03-13·CVSS 7.5
CVE-2018-0808 [HIGH] ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application.
The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
ASP.NET: ASP.NET
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:N/A;DOS:Permanent
Remediation:
No detection rules found.
No public exploits indexed.
Krebs
Flash, Windows Users: It’s Time to Patch
blogs_krebs·2018-03-13·CVSS 7.5
[HIGH] Flash, Windows Users: It’s Time to Patch
Adobe and Microsoft each pushed critical security updates to their products today. Adobe’s got a new version of Flash Player available, and Microsoft released 14 updates covering more than 75 vulnerabilities, two of which were publicly disclosed prior to today’s patch release.
The Microsoft updates affect all supported Windows operating systems, as well as all supported versions of Internet Explorer/Edge , Office , Sharepoint and Exchange Server .
All of the critical vulnerabilities from Microsoft are in browsers and browser-related technologies, according to a post from security firm Qualys .
“It is recommended that these be prioritized for workstation-type devices,” wrote Jimmy Graham , director of product management at Qualys. “Any system that accesses the Internet via a browser shou
Krebs
Flash, Windows Users: It’s Time to Patch
blogs_krebs·2018-03-13·CVSS 7.5
[HIGH] Flash, Windows Users: It’s Time to Patch
Adobe and Microsoft each pushed critical security updates to their products today. Adobe’s got a new version of Flash Player available, and Microsoft released 14 updates covering more than 75 vulnerabilities, two of which were publicly disclosed prior to today’s patch release.
All of the critical vulnerabilities from Microsoft are in browsers and browser-related technologies, according to a post from security firm Qualys.
“It is recommended that these be prioritized for workstation-type devices,” wrote Jimmy Graham, director of product management at Qualys. “Any system that accesses the Internet via a browser should be patched.”
The Microsoft vulnerabilities that were publicly disclosed prior to today involve Microsoft Exchange Server 2010 through 2016 editions (CVE-2018-0940) and ASP.N
Talos
Microsoft Patch Tuesday - March 2018
blogs_talos·2018-03-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - March 2018
### Microsoft Patch Tuesday - March 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 74 new vulnerabilities, with 14 of them rated critical and 59 of them rated important. These vulnerabilities impact Internet Explorer, Edge, Exchange, Scripting Engine, Windows Shell and more.
#### Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated as critical.
The vulnerabilities rated as critical are listed below:
CVE-2018-0872 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0874 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0876 - Scripting Engine Memory Corruption Vulnerabi
Talos
Microsoft Patch Tuesday - March 2018
blogs_talos·2018-03-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - March 2018
## Microsoft Patch Tuesday - March 2018
## Microsoft Patch Tuesday - March 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 74 new vulnerabilities, with 14 of them rated critical and 59 of them rated important. These vulnerabilities impact Internet Explorer, Edge, Exchange, Scripting Engine, Windows Shell and more.
## Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated as critical.
The vulnerabilities rated as critical are listed below:
CVE-2018-0872 - Chakra Scripting Engine Memory Corruption Vulnerability CVE-2018-0874 - Chakra Scripting Engine Memory Corruption Vulnerability CVE-2018-0876 - Script
http://www.securityfocus.com/bid/103226http://www.securitytracker.com/id/1040504https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0808http://www.securityfocus.com/bid/103226http://www.securitytracker.com/id/1040504https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0808
2018-03-14
Published