CVE-2018-8284

CWE-94Code Injection4 documents4 sources
Severity
8.1HIGH
EPSS
30.2%
top 3.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 13

Description

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Micr

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages6 packages

NVDmicrosoft/.net_framework11 versions+10
CVEListV5microsoft/microsoft_.net_framework71 versions+70
NVDmicrosoft/project_server2010, 2013+1
NVDmicrosoft/sharepoint_server2010, 2013+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c5vc-j56m-8jj4: A remote code execution vulnerability exists when the Microsoft2022-05-13
CVEList
CVE-2018-8284: A remote code execution vulnerability exists when the Microsoft2018-07-11

📋Vendor Advisories

1
Microsoft
.NET Framework Remote Code Execution Injection Vulnerability2018-07-10
CVE-2018-8284 (HIGH CVSS 8.1) | A remote code execution vulnerabili | cvebase.io