CVE-2017-0248

HIGH

Microsoft .net Framework < 1.0.4 - Improper Certificate Validation

Title source: rule

Description

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

Exploits (1)

nomisec STUB
by rubenmamo · poc
https://github.com/rubenmamo/CVE-2017-0248-Test

Scores

CVSS v3 7.5
EPSS 0.0109
EPSS Percentile 77.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-295
Status draft

Affected Products (27)

microsoft/.net_framework
microsoft/.net_framework
microsoft/.net_framework
microsoft/.net_framework
microsoft/.net_framework
microsoft/.net_framework
microsoft/.net_framework
microsoft/.net_framework
nuget/Microsoft.AspNetCore.Mvc < 1.0.4NuGet
nuget/Microsoft.AspNetCore.Mvc.Core < 1.0.4NuGet
nuget/System.Net.Http < 4.1.2NuGet
nuget/System.Text.Encodings.Web < 4.0.1NuGet
nuget/System.Net.Http.WinHttpHandler < 4.0.1NuGet
nuget/System.Net.Security < 4.0.1NuGet
nuget/System.Net.WebSockets.Client < 4.0.1NuGet
... and 12 more

Timeline

Published May 12, 2017
Tracked Since Feb 18, 2026