CVE-2018-8421: Input Validation
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-8421?
CVE-2018-8421 is a remote code execution vulnerability in Microsoft .NET Framework.
What software is affected by CVE-2018-8421?
Microsoft .NET Framework versions 2.0, 3.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, and 4.7.2 are affected by CVE-2018-8421.
What is the severity of CVE-2018-8421?
CVE-2018-8421 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2018-8421?
To fix CVE-2018-8421, update your Microsoft .NET Framework installation to a patched version provided by Microsoft.
Where can I find more information about CVE-2018-8421?
You can find more information about CVE-2018-8421 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/105222), [SecurityTracker](http://www.securitytracker.com/id/1041636), [Microsoft Security Advisory](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8421).