CVE-2018-8356: Medium severity Microsoft .NET Framework vulnerability
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-8356?
CVE-2018-8356 is a security feature bypass vulnerability in Microsoft .NET Framework components.
Which versions of .NET Framework are affected by CVE-2018-8356?
CVE-2018-8356 affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2.
How severe is the vulnerability CVE-2018-8356?
The severity of CVE-2018-8356 is medium, with a severity value of 5.5.
How does CVE-2018-8356 work?
CVE-2018-8356 occurs when Microsoft .NET Framework components fail to correctly validate certificates, leading to a security feature bypass.
Where can I find more information about CVE-2018-8356?
More information about CVE-2018-8356 can be found on the following websites: http://www.securityfocus.com/bid/104664, http://www.securitytracker.com/id/1041257, https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8356.