CVE-2013-1337: High severity Microsoft .NET Framework vulnerability
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1337?
CVE-2013-1337 has a severity rating of important due to potential unauthorized access.
How do I fix CVE-2013-1337?
To fix CVE-2013-1337, apply the latest security updates provided by Microsoft for the .NET Framework.
What systems are affected by CVE-2013-1337?
CVE-2013-1337 specifically affects Microsoft .NET Framework version 4.5.
What type of attack does CVE-2013-1337 permit?
CVE-2013-1337 allows remote attackers to bypass authentication via crafted queries to certain WCF endpoints.
Is CVE-2013-1337 specific to any protocols?
Yes, CVE-2013-1337 particularly concerns authentication over HTTPS.