CVE-2018-8284
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Affected (19)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp2 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2016 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.5.2 |
Configuration E
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration F
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1607 |
Microsoft Windows Server 2016 | All versions |
Configuration G
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 7 | All versions |
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Server 2012 | All versions |
Configuration I
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1709 |
Microsoft Windows Server | Version 1709 |
Configuration J
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1803 |
Microsoft Windows Server | Version 1803 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.7.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1703 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2010 sp2 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2013 sp1 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2010 sp2 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2010 sp2 |
References (6)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.