CVE-2017-0248

HIGH

Microsoft .net Framework < 1.0.4 - Improper Certificate Validation

Title source: rule

Description

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

Exploits (1)

nomisec STUB
by rubenmamo · poc
https://github.com/rubenmamo/CVE-2017-0248-Test

Scores

CVSS v3 7.5
EPSS 0.0109
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (28)
microsoft/.net_framework 2.0 sp2
microsoft/.net_framework 3.5
microsoft/.net_framework 3.5.1
microsoft/.net_framework 4.5.2
microsoft/.net_framework 4.6
microsoft/.net_framework 4.6.1
microsoft/.net_framework 4.6.2
microsoft/.net_framework 4.7
Microsoft Corporation/Microsoft .NET Framework Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7
nuget/Microsoft.AspNetCore.Mvc 1.0.0 - 1.0.4NuGet
... and 18 more
Published May 12, 2017
Tracked Since Feb 18, 2026