PT-2013-2056 · Microsoft · .Net Framework+3
Published
2013-01-09
·
Updated
2023-12-07
·
CVE-2013-0005
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 3.5 through 4
Management OData IIS Extension on Windows Server 2012
Description
A denial of service issue exists in the OData protocol implementation, allowing remote attackers to cause a denial of service via crafted values in HTTP requests. This could cause the server or service to stop responding and restart.
Recommendations
For Microsoft .NET Framework versions 3.5 through 4, update to a version that includes the fix for this issue.
For Management OData IIS Extension on Windows Server 2012, restrict access to the OData endpoint to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider disabling the WCF Replace function in the Open Data protocol implementation until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework
Management Odata Iis Extension
Wcf
Windows Server 2012