7.5
CVSSv3

CVE-2018-0786

Published: 10/01/2018 Updated: 12/08/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net core 1.0

microsoft .net core 2.0

microsoft powershell core 6.0

microsoft .net_framework 3.0

microsoft .net_framework 2.0

microsoft .net_framework 3.5

microsoft .net_framework 3.5.1

microsoft .net_framework 4.5.2

microsoft .net_framework 4.6

microsoft .net_framework 4.6.1

microsoft .net_framework 4.7

microsoft .net_framework 4.6.2

microsoft .net_framework 4.7.1

Vendor Advisories

Microsoft NET Framework 20 SP2, 30 SP2, 35, 351, 452, 46, 461, 462, 47, 471, NET Core 10 and 20, and PowerShell Core 600 allow a security feature bypass vulnerability due to the way certificates are validated, aka "NET Security Feature Bypass Vulnerability" ...

Recent Articles

Don't just grab your CPU bug updates – there's a nasty hole in Office, too
The Register • Shaun Nichols in San Francisco • 09 Jan 2018

It's 2018 and a Word doc can still pwn your Windows computer

Patch Tuesday In case you've been hiding under a rock for the entirety of this new year (and we don't blame you if you have) there are a handful of major security flaws that have been dominating the news, and feature prominently in this month's Patch Tuesday update load. First, let's look at the latest developments in the Meltdown/Spectre saga: Nvidia has got around to kicking out graphics driver updates that address the Spectre flaws present in its code – for example, here are some patches fo...