CVE-2017-0248: High severity microsoft .net framework 4 vulnerability
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0248?
CVE-2017-0248 is rated as critical due to its potential to allow attackers to bypass security features.
How do I fix CVE-2017-0248?
To mitigate CVE-2017-0248, update your Microsoft .NET Framework to a version that is not vulnerable, such as 4.7 or later.
What versions of Microsoft .NET Framework are affected by CVE-2017-0248?
CVE-2017-0248 affects Microsoft .NET Framework versions 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, and 4.7.
Can CVE-2017-0248 affect applications using .NET Framework?
Yes, applications relying on the affected versions of the .NET Framework are vulnerable to CVE-2017-0248.
Is there a workaround for CVE-2017-0248 if I cannot immediately update?
While updating is the best solution, temporarily strengthening certificate validation might help mitigate the risk until a full update can be applied.