Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2018-8356

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.

CVSS v3:

  • Severity: Medium
  • Score: 5.5
  • AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVSS v2:

  • Severity: Low
  • Score: 2.1
  • AV:L/AC:L/Au:N/C:N/I:P/A:N
Software From Fixed in
microsoft / .net_framework 3.0-sp2 3.0-sp2.x
microsoft / .net_framework 3.5 3.5.x
microsoft / .net_framework 3.5.1 3.5.1.x
microsoft / .net_framework 4.5.2 4.5.2.x
microsoft / .net_framework 4.6 4.6.x
microsoft / .net_framework 4.6.2 4.6.2.x
microsoft / .net_framework 4.7 4.7.x
microsoft / .net_framework 4.7.1 4.7.1.x
microsoft / .net_framework 4.7.2 4.7.2.x
microsoft / .net_framework 4.6.1 4.6.1.x
microsoft / powershell_core 6.1 6.1.x
microsoft / powershell_core 6.0 6.0.x
microsoft / .net_core 2.0 2.0.x
microsoft / .net_core 1.0 1.0.x
microsoft / .net_core 1.1 1.1.x
microsoft / .net_framework_developer_pack 4.7.2 4.7.2.x
microsoft / asp.net_core 1.0 1.0.x
microsoft / asp.net_core 1.1 1.1.x
microsoft / asp.net_core 2.0 2.0.x
System.Private.ServiceModel 4.0.0 4.1.3
System.Private.ServiceModel 4.3.0 4.3.3
System.Private.ServiceModel 4.4.0 4.4.4
System.Private.ServiceModel 4.5.0 4.5.3
System.ServiceModel.Duplex 4.3.0 4.3.3
System.ServiceModel.Duplex 4.4.0 4.4.4
System.ServiceModel.Duplex 4.5.0 4.5.3
System.ServiceModel.Duplex 4.0.0 4.0.4
System.ServiceModel.Http 4.3.0 4.3.3
System.ServiceModel.Http 4.4.0 4.4.4
System.ServiceModel.Http 4.5.0 4.5.3
System.ServiceModel.Http 4.0.0 4.1.3
System.ServiceModel.NetTcp 4.3.0 4.3.3
System.ServiceModel.NetTcp 4.4.0 4.4.4
System.ServiceModel.NetTcp 4.5.0 4.5.3
System.ServiceModel.NetTcp 4.0.0 4.1.3
System.ServiceModel.Primitives 4.3.0 4.3.3
System.ServiceModel.Primitives 4.4.0 4.4.4
System.ServiceModel.Primitives 4.5.0 4.5.3
System.ServiceModel.Primitives 4.0.0 4.1.3
System.ServiceModel.Security 4.3.0 4.3.3
System.ServiceModel.Security 4.4.0 4.4.4
System.ServiceModel.Security 4.5.0 4.5.3
System.ServiceModel.Security 4.0.0 4.0.4