CVE-2011-1977
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 21.37% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/.net framework · microsoft/chart control for microsoft .net framework
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/cas/techalerts/TA11-221A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-066
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12970
- http://www.us-cert.gov/cas/techalerts/TA11-221A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-066
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12970
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.