PT-2018-18563 · Microsoft · Net Core+2

Published

2018-07-10

·

Updated

2022-05-23

·

CVE-2018-8356

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 3.0 through 4.7.2 ASP.NET Core versions 1.0 through 2.0 .NET Core versions 1.0 through 2.0
Description A security feature bypass issue exists due to incorrect certificate validation in Microsoft .NET Framework components. This allows attackers to utilize expired certificates.
Recommendations For Microsoft .NET Framework versions 3.0 through 4.7.2, update to a version that correctly validates certificates. For ASP.NET Core versions 1.0 through 2.0, update to a version that correctly validates certificates. For .NET Core versions 1.0 through 2.0, update to a version that correctly validates certificates.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8356
GHSA-P9WX-V264-Q34P

Affected Products

Net Core
.Net Framework
Asp.Net Core