| Title | Microsoft .NET Framework および .NET Core におけるサービス運用妨害 (DoS) にされる脆弱性 |
|---|---|
| Summary | Microsoft .NET Framework および .NET Core には、XML ドキュメントを不適切に処理する場合、サービス運用妨害 (DoS) にされる脆弱性が存在します。 ベンダは、本脆弱性を「.NET および .NET Core のサービス拒否の脆弱性」として公開しています。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | May 8, 2018, midnight |
| Registration Date | June 15, 2018, 2:33 p.m. |
| Last Update | June 15, 2018, 2:33 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.5 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS2.0 : 警告 | |
| Score | 5 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| マイクロソフト |
| .NET Core 2.0 |
| Microsoft .NET Framework 2.0 SP2 |
| Microsoft .NET Framework 3.5 |
| Microsoft .NET Framework 3.5.1 |
| Microsoft .NET Framework 4.5.2 |
| Microsoft .NET Framework 4.6 |
| Microsoft .NET Framework 4.6.1 |
| Microsoft .NET Framework 4.6.2 |
| Microsoft .NET Framework 4.7 |
| Microsoft .NET Framework 4.7.1 |
| Microsoft .NET Framework 4.7.2 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2018年06月15日] 掲載 |
June 15, 2018, 2:33 p.m. |
| Summary | A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2. |
|---|---|
| Publication Date | May 10, 2018, 4:29 a.m. |
| Registration Date | March 1, 2021, 6:38 p.m. |
| Last Update | Nov. 21, 2024, 12:38 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_core:2.0:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||||
| 3 | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||||
| 4 | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||||
| 5 | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||||
| 6 | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||||
| 7 | cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* | ||||
| 8 | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||||
| 9 | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||||
| 10 | cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:* | ||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* | ||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||||
| 3 | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||||
| 4 | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||||
| 5 | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* | ||||
| 6 | cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* | ||||
| 7 | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||||
| Configuration6 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||||
| Configuration7 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||||
| Configuration8 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||||
| Configuration9 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||||
| 3 | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||||
| 4 | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* | ||||
| 5 | cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* | ||||
| 6 | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||||
| Configuration10 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||||
| Configuration11 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||||
| Configuration12 | or higher | or less | more than | less than | |
| cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||||