#VU7458 Denial of service in Microsoft .NET Framework - CVE-2017-8585

 

#VU7458 Denial of service in Microsoft .NET Framework - CVE-2017-8585

Published: July 11, 2017 / Updated: July 11, 2017


Vulnerability identifier: #VU7458
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-8585
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft .NET Framework
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper handling of web requests by Microsoft Common Object Runtime Library in .NET  application. A remote attacker can supply specially crafted requests and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Install updates from vendor's website.

External links