CVE-2018-0765: XEE
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-0765?
CVE-2018-0765 refers to a denial of service vulnerability in .NET and .NET Core when processing XML documents.
Which software is affected by CVE-2018-0765?
CVE-2018-0765 affects Microsoft .NET Framework versions 2.0, 3.0, 4.7.1, and .NET Core 2.0.
What is the severity of CVE-2018-0765?
CVE-2018-0765 has a severity rating of high with a CVSS score of 7.5.
How does CVE-2018-0765 impact my system?
CVE-2018-0765 can be exploited to cause a denial of service on systems running affected versions of .NET Framework and .NET Core.
Is there a fix available for CVE-2018-0765?
Yes, Microsoft has released security updates to address CVE-2018-0765. It is recommended to install the latest updates to protect against this vulnerability.