cbcvebase.
CVE-2018-8284
published 2018-07-11

CVE-2018-8284: A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection…

PriorityP262high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
39.55%
98.4th percentile
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.

Affected

110 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires passing specific input to an application utilizing susceptible .NET methods — monitor for unusual or malformed input to .NET-based applications, particularly those exposed to remote users.
  • Successful exploitation allows attacker to install programs, view/change/delete data, or create new accounts with full user rights — monitor for unexpected process spawning, account creation, or file system changes from .NET application worker processes.
  • SharePoint Server deployments running affected .NET Framework versions are also at risk — ensure .NET patch coverage is validated on SharePoint hosts specifically.
  • ·Vulnerability is a remote code injection via improper input validation in .NET Framework; the fix corrects input validation logic — detection should focus on behavioral indicators rather than static signatures, as no public exploit or specific payload pattern is disclosed.
  • ·As of advisory publication, the vulnerability was not publicly exploited and exploitation was rated 'Less Likely' for both latest and older software releases — lower immediate threat priority but patching remains required.

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.