Microsoft. NET Framework security features Bypass Vulnerability (CVE-2018-0786)
Microsoft. NET Framework security features Bypass Vulnerability (CVE-2018-0786)
Release date:
Updated on:
Affected Systems:
Microsoft. NET Framework 4.7
Microsoft. NET Framework 4.6.2
Microsoft. NET Framework 4.6.1
Microsoft. NET Framework 4.6
Microsoft. NET Framework 4.5.2
Microsoft. NET Framework 3.5.1
Microsoft. NET Framework 3.5
Microsoft. NET Framework 3.0 SP2
Microsoft. NET Framework 2.0 SP2
Microsoft ASP. NET Core 2.0
Microsoft ASP. NET Core 1.0
Description:
CVE (CAN) ID: CVE-2018-0786
ASP. NET Core is a new open-source and cross-platform framework for building modern cloud-based applications connected to the Internet, such as Web applications, IoT applications, and mobile backend applications.
Microsoft. NET Framework applications have a security function bypass vulnerability in certificate verification, which allows attackers to bypass certain security functions.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Microsoft
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0786