PT-2016-1983 · Microsoft · .Net Framework

Publicado

2016-05-10

·

Atualizado

2018-10-12

·

CVE-2016-0149

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 2.0 SP2 through 4.6.1
Description The issue allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream. An attacker who successfully exploited this vulnerability could decrypt encrypted SSL/TLS traffic by first injecting unencrypted data into the secure channel and then performing a man-in-the-middle attack between the targeted client and a legitimate server.
Recommendations For Microsoft .NET Framework versions 2.0 SP2 through 4.6.1, consider disabling the use of TLS/SSL protocol until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. Avoid using the encryption component of Microsoft .NET Framework in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01316
CVE-2016-0149

Produtos afetados

.Net Framework