CVE-2018-8260: Input Validation
Published Jul 11, 2018
·Updated
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
Affected Software
28 affected components
Microsoft .NET Framework=4.7.2
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server=1709
Microsoft Windows Server=1803
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
All of the following
Microsoft .NET Framework=4.7.2
Any of the following
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server=1709
Microsoft Windows Server=1803
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Event History
Jul 11, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8260?
CVE-2018-8260 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2018-8260?
To fix CVE-2018-8260, update the .NET Framework to a supported version that addresses this vulnerability.
3
Which versions of .NET Framework are affected by CVE-2018-8260?
CVE-2018-8260 specifically affects .NET Framework 4.7.2.
4
What type of vulnerability is CVE-2018-8260?
CVE-2018-8260 is a Remote Code Execution vulnerability.
5
Can my Windows 10 system be affected by CVE-2018-8260?
Yes, if your system is running .NET Framework 4.7.2, it is vulnerable to CVE-2018-8260.