CVE-2018-8517
published 2018-12-12CVE-2018-8517: A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability."…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
5.83%
92.3th percentile
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6m2p-4g25-m3gv: A denial of service vulnerability exists when
ghsa_unreviewed·2022-05-13
CVE-2018-8517 [HIGH] GHSA-6m2p-4g25-m3gv: A denial of service vulnerability exists when
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Microsoft
.NET Framework Denial Of Service Vulnerability
vendor_msrc·2018-12-11·CVSS 7.5
CVE-2018-8517 [HIGH] .NET Framework Denial Of Service Vulnerability
.NET Framework Denial Of Service Vulnerability
Description: A denial of service vulnerability exists when .NET Framework improperly handles special web requests.
An attacker who successfully exploited this vulnerability could cause a denial of service against an .NET Framework web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Framework web application handles web requests.
.NET Framework: .NET Framework
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-12
Published