SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-1978

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser…

MEDIUM 4.3EPSS 20.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 20.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
20.21% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
microsoft/.net framework
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.