PT-2018-18563 · Microsoft · Net Core+2
Published
2018-07-10
·
Updated
2022-05-23
·
CVE-2018-8356
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 3.0 through 4.7.2
ASP.NET Core versions 1.0 through 2.0
.NET Core versions 1.0 through 2.0
Description
A security feature bypass issue exists due to incorrect certificate validation in Microsoft .NET Framework components. This allows attackers to utilize expired certificates.
Recommendations
For Microsoft .NET Framework versions 3.0 through 4.7.2, update to a version that correctly validates certificates.
For ASP.NET Core versions 1.0 through 2.0, update to a version that correctly validates certificates.
For .NET Core versions 1.0 through 2.0, update to a version that correctly validates certificates.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net Core
.Net Framework
Asp.Net Core