Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.813487
Category:Windows : Microsoft Bulletins
Title:Microsoft .NET Framework Multiple Vulnerabilities (KB4338424)
Summary:This host is missing an important security; update according to Microsoft KB4338424
Description:Summary:
This host is missing an important security
update according to Microsoft KB4338424

Vulnerability Insight:
Multiple flaws exist due to:

- An error when Microsoft .NET Framework components do not correctly validate
certificates.

- An error in the way how .NET Framework activates COM objects.

- An error when the Microsoft .NET Framework fails to validate input properly.

Vulnerability Impact:
Successful exploitation will allow an attacker
to gain elevated privileges, bypass security restrictions and take control of an
affected system allowing to install programs or view data, change data, delete
data or create new accounts with full user rights.

Affected Software/OS:
Microsoft .NET Framework 3.5 SP1 for Microsoft Windows 8.1 and Microsoft Windows Server 2012 R2.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-8356
BugTraq ID: 104664
http://www.securityfocus.com/bid/104664
http://www.securitytracker.com/id/1041257
Common Vulnerability Exposure (CVE) ID: CVE-2018-8284
BugTraq ID: 104667
http://www.securityfocus.com/bid/104667
Common Vulnerability Exposure (CVE) ID: CVE-2018-8202
BugTraq ID: 104665
http://www.securityfocus.com/bid/104665
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.