PT-2017-10475 · Microsoft · .Net Framework
Published
2017-05-09
·
Updated
2019-10-03
·
CVE-2017-0248
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 2.0 through 4.7
Description
A security issue exists where components do not completely validate certificates, allowing an attacker to present a certificate that is marked invalid for a specific use. The component may use it for that purpose, disregarding the Enhanced Key Usage taggings. This could enable an attacker to bypass security features.
Recommendations
For Microsoft .NET Framework versions 2.0 through 4.7, ensure that all certificates are properly validated, considering their specific use and Enhanced Key Usage taggings. As a temporary workaround, consider restricting the use of certificates that are marked invalid for specific uses until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework