Denial of service in Microsoft .NET Framework - CVE-2017-8585

 

Denial of service in Microsoft .NET Framework - CVE-2017-8585

Published: July 11, 2017 / Updated: July 11, 2017


Vulnerability identifier: #VU7458
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8585
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper handling of web requests by Microsoft Common Object Runtime Library in .NET  application. A remote attacker can supply specially crafted requests and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Microsoft .NET Framework
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2017-8585

Install updates from vendor's website.

IBM Robotic Process Automation - addressed in versions 21.0.7.16, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.16, 23.0.16

External References

Related Security Bulletins