Security restrictions bypass in Microsoft products - CVE-2018-8171
Published: July 10, 2018 / Updated: July 10, 2018
Vulnerability identifier: #VU13773
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8171
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists in ASP.NET due to the number of incorrect login attempts is not validated. A remote unauthenticated attacker can try an infinite number of authentication attempts and bypass security restrictions to conduct further attacks.
Affected software
ASP.NET Core MVC
ASP.NET Web Pages
ASP.NET MVC
ASP.NET Web Pages
ASP.NET MVC
How to mitigate CVE-2018-8171
Install updates from vendor's website.