First published: Tue Jul 11 2017(Updated: )
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/dotnetcore | <1.0.7 | 1.0.7 |
redhat/dotnetcore | <1.1.4 | 1.1.4 |
Microsoft .NET Framework 4 | =4.6 | |
Microsoft .NET Framework 4 | =4.6.1 | |
Microsoft .NET Framework 4 | =4.6.2 | |
Microsoft .NET Framework 4 | =4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8585 is considered a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2017-8585, it is recommended to update the Microsoft .NET Framework to the latest version provided by Microsoft.
CVE-2017-8585 affects Microsoft .NET Framework versions 4.6, 4.6.1, 4.6.2, and 4.7.
CVE-2017-8585 is a denial of service vulnerability caused by improper handling of culture parameters.
Yes, an attacker can exploit CVE-2017-8585 remotely by sending specially crafted requests to a vulnerable .NET web application.