CVE-2016-0149: Infoleak
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0149?
CVE-2016-0149 is rated as important by Microsoft due to its potential for information disclosure.
How do I fix CVE-2016-0149?
To mitigate CVE-2016-0149, you should apply the security updates provided by Microsoft for all affected .NET Framework versions.
What are the affected software versions of CVE-2016-0149?
CVE-2016-0149 affects Microsoft .NET Framework versions 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1.
What kind of attack does CVE-2016-0149 allow?
CVE-2016-0149 allows man-in-the-middle attackers to obtain sensitive cleartext information.
Is CVE-2016-0149 a critical vulnerability?
Though CVE-2016-0149 is not classified as critical, it poses significant risks due to the potential exposure of sensitive data.