CVE-2017-0248

HIGH

.NET Framework Security Feature Bypass via Improper Certificate Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-0248. PoCs published by rubenmamo.

AI-analyzed exploit summary The repository contains only an AssemblyInfo.cs file with metadata for a CVE-2017-0248 test project, but no actual exploit code or technical details. This appears to be a placeholder or incomplete project.

Description

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

Exploits (1)

nomisec STUB
by rubenmamo · poc
https://github.com/rubenmamo/CVE-2017-0248-Test

The repository contains only an AssemblyInfo.cs file with metadata for a CVE-2017-0248 test project, but no actual exploit code or technical details. This appears to be a placeholder or incomplete project.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Unknown (CVE-2017-0248 is related to Microsoft Windows, but no specific version is mentioned)
No auth needed
Prerequisites: None identified
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98117
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038458

Scores

CVSS v3 7.5
EPSS 0.0109
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (28)
microsoft/.net_framework 2.0 sp2
microsoft/.net_framework 3.5
microsoft/.net_framework 3.5.1
microsoft/.net_framework 4.5.2
microsoft/.net_framework 4.6
microsoft/.net_framework 4.6.1
microsoft/.net_framework 4.6.2
microsoft/.net_framework 4.7
Microsoft Corporation/Microsoft .NET Framework Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7
nuget/Microsoft.AspNetCore.Mvc 1.0.0 - 1.0.4NuGet
... and 18 more
Published May 12, 2017
Tracked Since Feb 18, 2026