CVE Vulnerabilities

CVE-2017-0248

Improper Certificate Validation

Published: May 12, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka .NET Security Feature Bypass Vulnerability.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
.net_frameworkMicrosoft2.0-sp2 (including)2.0-sp2 (including)
.net_frameworkMicrosoft3.5 (including)3.5 (including)
.net_frameworkMicrosoft3.5.1 (including)3.5.1 (including)
.net_frameworkMicrosoft4.5.2 (including)4.5.2 (including)
.net_frameworkMicrosoft4.6 (including)4.6 (including)
.net_frameworkMicrosoft4.6.1 (including)4.6.1 (including)
.net_frameworkMicrosoft4.6.2 (including)4.6.2 (including)
.net_frameworkMicrosoft4.7 (including)4.7 (including)

Potential Mitigations

References