CVE-2018-8416
published 2018-11-14CVE-2018-8416: A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
PriorityP339medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
7.26%
93.6th percentile
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | net_core | — | — |
| msrc | net_core_2.1 | — | — |
| msrc | powershell_core_6.1 | — | — |
| msrc | powershell_core_6.2 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Tampering vulnerability in .NET Core
osv·2022-05-13
CVE-2018-8416 [MEDIUM] Tampering vulnerability in .NET Core
Tampering vulnerability in .NET Core
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
GHSA
Tampering vulnerability in .NET Core
ghsa·2022-05-13
CVE-2018-8416 [MEDIUM] Tampering vulnerability in .NET Core
Tampering vulnerability in .NET Core
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
OSV
CVE-2018-8416: A tampering vulnerability exists when
osv·2018-11-14·CVSS 6.5
CVE-2018-8416 [MEDIUM] CVE-2018-8416: A tampering vulnerability exists when
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
Red Hat
Core: Arbitrary file and directory creation
vendor_redhat·2018-11-13·CVSS 6.5
CVE-2018-8416 [MEDIUM] Core: Arbitrary file and directory creation
Core: Arbitrary file and directory creation
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
Package: rh-dotnetcore10-dotnetcore (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore11-dotnetcore (.NET Core 1.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet20-dotnet (.NET Core 2.0 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
Microsoft
.NET Core Tampering Vulnerability
vendor_msrc·2018-11-13·CVSS 6.5
CVE-2018-8416 [MEDIUM] .NET Core Tampering Vulnerability
.NET Core Tampering Vulnerability
Description: A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories.
To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system.
The security update fixes the vulnerability by ensuring .NET Core properly handles files.
.NET Core: .NET Core
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Tampering
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Explo
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105798http://www.securitytracker.com/id/1042128https://access.redhat.com/errata/RHSA-2018:3676https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8416http://www.securityfocus.com/bid/105798http://www.securitytracker.com/id/1042128https://access.redhat.com/errata/RHSA-2018:3676https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8416
2018-11-14
Published