CVE-2018-8284: Code Injection
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8284?
CVE-2018-8284 is rated as critical because it allows remote code execution.
How do I fix CVE-2018-8284?
To fix CVE-2018-8284, it is recommended to apply the latest security updates provided by Microsoft for the affected versions of the .NET Framework.
Which versions of .NET Framework are affected by CVE-2018-8284?
CVE-2018-8284 affects Microsoft .NET Framework versions 2.0, 3.0, 3.5, 4.6.1, 4.6.2, 4.7, 4.7.1, and 4.7.2.
What is a remote code execution vulnerability in CVE-2018-8284?
A remote code execution vulnerability like CVE-2018-8284 allows attackers to execute arbitrary code on a target system without physical access.
Is there a workaround for CVE-2018-8284?
There are no known workarounds for CVE-2018-8284; applying the security updates from Microsoft is essential to mitigate this vulnerability.