Security restrictions bypass in Microsoft products - CVE-2018-8171

 

Security restrictions bypass in Microsoft products - CVE-2018-8171

Published: July 10, 2018 / Updated: July 10, 2018


Vulnerability identifier: #VU13773
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8171
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists in ASP.NET due to the number of incorrect login attempts is not validated. A remote unauthenticated attacker can try an infinite number of authentication attempts and bypass security restrictions to conduct further attacks.

Affected software

ASP.NET Core MVC
ASP.NET Web Pages
ASP.NET MVC

How to mitigate CVE-2018-8171

Install updates from vendor's website.


External References

Related Security Bulletins