CVE-2018-8540: Code Injection
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-8540?
CVE-2018-8540 is a remote code execution vulnerability in the Microsoft .NET Framework.
What is the severity of CVE-2018-8540?
The severity of CVE-2018-8540 is critical with a CVSS score of 9.8.
Which versions of Microsoft .NET Framework are affected by CVE-2018-8540?
Microsoft .NET Framework versions 4.6, 3.5, 4.7, 4.7.1, and 4.7.2 are affected by CVE-2018-8540.
How does CVE-2018-8540 affect Microsoft Windows 10?
CVE-2018-8540 does not affect Microsoft Windows 10.
Where can I find more information about CVE-2018-8540?
You can find more information about CVE-2018-8540 on the SecurityFocus and Microsoft Security Response Center websites.