CVE-2018-0786: High severity microsoft .net core runtime vulnerability
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-0786?
CVE-2018-0786 is a security feature bypass vulnerability in Microsoft .NET Framework and PowerShell Core.
How severe is CVE-2018-0786?
CVE-2018-0786 has a high severity with a CVSS score of 7.5.
Which software versions are affected by CVE-2018-0786?
CVE-2018-0786 affects Microsoft .NET Framework versions 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0.
How can I fix CVE-2018-0786?
To fix CVE-2018-0786, Microsoft has released security updates. It is recommended to apply the latest updates for affected software versions.
Where can I find more information about CVE-2018-0786?
You can find more information about CVE-2018-0786 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/102380), [SecurityTracker](http://www.securitytracker.com/id/1040152), [Microsoft Security Guidance Advisory](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0786).