CVE-2018-8416: Medium severity asp.net core vulnerability
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
Other sources
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories.
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8416
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-8416?
CVE-2018-8416 is a tampering vulnerability in .NET Core 2.1.
How does the CVE-2018-8416 vulnerability occur?
The vulnerability occurs when .NET Core improperly handles specially crafted files.
What is the severity of CVE-2018-8416?
The severity of CVE-2018-8416 is medium (CVSS score: 6.5).
Which software is affected by CVE-2018-8416?
The affected software is Microsoft ASP.NET Core 2.1.
How can I fix the CVE-2018-8416 vulnerability?
To fix the vulnerability, it is recommended to apply the relevant security patches provided by Microsoft.