CVE-2019-0657

Severity
5.9MEDIUM
EPSS
8.0%
top 7.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 14

Description

A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages22 packages

NVDmicrosoft/.net_framework11 versions+10
CVEListV5microsoft/microsoft_.net_framework_2.0Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2

Patches

🔴Vulnerability Details

3
GHSA
Improper Input Validation in .Net Framework API's2022-05-14
OSV
Improper Input Validation in .Net Framework API's2022-05-14
CVEList
CVE-2019-0657: A vulnerability exists in certain2019-03-06

📋Vendor Advisories

2
Red Hat
dotnet: Domain-spoofing attack in System.Uri2019-02-12
Microsoft
.NET Framework and Visual Studio Spoofing Vulnerability2019-02-12

💬Community

1
Bugzilla
CVE-2019-0657 dotnet: Domain-spoofing attack in System.Uri2019-02-08