PT-2017-10475 · Microsoft · .Net Framework

Published

2017-05-09

·

Updated

2019-10-03

·

CVE-2017-0248

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 2.0 through 4.7
Description A security issue exists where components do not completely validate certificates, allowing an attacker to present a certificate that is marked invalid for a specific use. The component may use it for that purpose, disregarding the Enhanced Key Usage taggings. This could enable an attacker to bypass security features.
Recommendations For Microsoft .NET Framework versions 2.0 through 4.7, ensure that all certificates are properly validated, considering their specific use and Enhanced Key Usage taggings. As a temporary workaround, consider restricting the use of certificates that are marked invalid for specific uses until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0248
GHSA-CH6P-4JCM-H8VH

Affected Products

.Net Framework