CVE-2017-0248
HIGHMicrosoft .net Framework < 1.0.4 - Improper Certificate Validation
Title source: ruleDescription
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0109
EPSS Percentile
78.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-295
Status
published
Products (28)
microsoft/.net_framework
2.0 sp2
microsoft/.net_framework
3.5
microsoft/.net_framework
3.5.1
microsoft/.net_framework
4.5.2
microsoft/.net_framework
4.6
microsoft/.net_framework
4.6.1
microsoft/.net_framework
4.6.2
microsoft/.net_framework
4.7
Microsoft Corporation/Microsoft .NET Framework
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7
nuget/Microsoft.AspNetCore.Mvc
1.0.0 - 1.0.4NuGet
... and 18 more
Published
May 12, 2017
Tracked Since
Feb 18, 2026