CVE-2018-8356
Summary
| CVE | CVE-2018-8356 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-11 00:29:00 UTC |
| Updated | 2022-05-23 17:29:00 UTC |
| Description | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | .net Core | 1.0 | All | All | All |
| Application | Microsoft | .net Core | 1.1 | All | All | All |
| Application | Microsoft | .net Core | 2.0 | All | All | All |
| Application | Microsoft | .net Core | 1.0 | All | All | All |
| Application | Microsoft | .net Core | 1.1 | All | All | All |
| Application | Microsoft | .net Core | 2.0 | All | All | All |
| Application | Microsoft | .net Framework | 3.0 | sp2 | All | All |
| Application | Microsoft | .net Framework | 3.5 | All | All | All |
| Application | Microsoft | .net Framework | 3.5.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.5.2 | All | All | All |
| Application | Microsoft | .net Framework | 4.6 | All | All | All |
| Application | Microsoft | .net Framework | 4.6.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.6.2 | All | All | All |
| Application | Microsoft | .net Framework | 4.7 | All | All | All |
| Application | Microsoft | .net Framework | 4.7.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.7.2 | All | All | All |
| Application | Microsoft | .net Framework | 3.0 | sp2 | All | All |
| Application | Microsoft | .net Framework | 3.5 | All | All | All |
| Application | Microsoft | .net Framework | 3.5.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.5.2 | All | All | All |
| Application | Microsoft | .net Framework | 4.6 | All | All | All |
| Application | Microsoft | .net Framework | 4.6.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.6.2 | All | All | All |
| Application | Microsoft | .net Framework | 4.7 | All | All | All |
| Application | Microsoft | .net Framework | 4.7.1 | All | All | All |
| Application | Microsoft | .net Framework | 4.7.2 | All | All | All |
| Application | Microsoft | .net Framework Developer Pack | 4.7.2 | All | All | All |
| Application | Microsoft | .net Framework Developer Pack | 4.7.2 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.0 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.1 | All | All | All |
| Application | Microsoft | Asp.net Core | 2.0 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.0 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.1 | All | All | All |
| Application | Microsoft | Asp.net Core | 2.0 | All | All | All |
| Application | Microsoft | Powershell Core | 6.0 | All | All | All |
| Application | Microsoft | Powershell Core | 6.1 | All | All | All |
| Application | Microsoft | Powershell Core | 6.0 | All | All | All |
| Application | Microsoft | Powershell Core | 6.1 | All | All | All |
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1703 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1709 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1803 | All | All | All |
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1703 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1709 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1803 | All | All | All |
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows 8.1 | All | All | All | All |
| Operating System | Microsoft | Windows 8.1 | All | All | All | All |
| Operating System | Microsoft | Windows Rt 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows Rt 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows Server | 1803 | All | All | All |
| Operating System | Microsoft | Windows Server | 1803 | All | All | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2012 | All | All | All | All |
| Operating System | Microsoft | Windows Server 2012 | r2 | All | All | All |
| Operating System | Microsoft | Windows Server 2012 | All | All | All | All |
| Operating System | Microsoft | Windows Server 2012 | r2 | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | All | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | All | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft .NET Multiple Flaws Let Remote Users Execute Arbitrary Code and Local Users Bypass Security and Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.