Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2017-0248

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N
Software From Fixed in
microsoft / .net_framework 4.5.2 4.5.2.x
microsoft / .net_framework 2.0-sp2 2.0-sp2.x
microsoft / .net_framework 4.6.1 4.6.1.x
microsoft / .net_framework 4.6 4.6.x
microsoft / .net_framework 4.6.2 4.6.2.x
microsoft / .net_framework 3.5 3.5.x
microsoft / .net_framework 3.5.1 3.5.1.x
microsoft / .net_framework 4.7 4.7.x
Microsoft.AspNetCore.Mvc 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Core 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Core 1.1.0 1.1.3
System.Net.Http 4.1.1 4.1.1.x
System.Net.Http 4.1.1 4.1.2
System.Net.Http 4.3.1 4.3.1.x
System.Net.Http 4.3.1 4.3.2
System.Text.Encodings.Web 4.0.0 4.0.0.x
System.Text.Encodings.Web 4.0.0 4.0.1
System.Text.Encodings.Web 4.3.0 4.3.0.x
System.Text.Encodings.Web 4.3.0 4.3.1
System.Net.Http.WinHttpHandler 4.0.0 4.0.0.x
System.Net.Http.WinHttpHandler 4.0.0 4.0.1
System.Net.Http.WinHttpHandler 4.3.0 4.3.0.x
System.Net.Http.WinHttpHandler 4.3.0 4.3.1
System.Net.Security 4.0.0 4.0.0.x
System.Net.Security 4.0.0 4.0.1
System.Net.Security 4.3.0 4.3.0.x
System.Net.Security 4.3.0 4.3.1
System.Net.WebSockets.Client 4.0.0 4.0.0.x
System.Net.WebSockets.Client 4.0.0 4.0.1
System.Net.WebSockets.Client 4.3.0 4.3.0.x
System.Net.WebSockets.Client 4.3.0 4.3.1
Microsoft.AspNetCore.Mvc.Abstractions 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Abstractions 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.ApiExplorer 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.ApiExplorer 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Cors 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Cors 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.DataAnnotations 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.DataAnnotations 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Formatters.Json 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Formatters.Json 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Formatters.Xml 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Formatters.Xml 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Localization 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Localization 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Razor.Host 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Razor.Host 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Razor 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Razor 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.TagHelpers 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.TagHelpers 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.ViewFeatures 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.ViewFeatures 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.WebApiCompatShim 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.WebApiCompatShim 1.1.0 1.1.3