Denial of service in Microsoft .NET Framework - CVE-2017-8585
Published: July 11, 2017 / Updated: July 11, 2017
Vulnerability identifier: #VU7458
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8585
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper handling of web requests by Microsoft Common Object Runtime Library in .NET application. A remote attacker can supply specially crafted requests and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to improper handling of web requests by Microsoft Common Object Runtime Library in .NET application. A remote attacker can supply specially crafted requests and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Microsoft .NET Framework
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2017-8585
Install updates from vendor's website.
IBM Robotic Process Automation - addressed in versions 21.0.7.16, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.16, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.16, 23.0.16