CVE-2011-3415
Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 22.95% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/windows 7 · microsoft/windows server 2003 · microsoft/windows server 2008 · microsoft/windows vista · microsoft/windows xp
- Source
- secure@microsoft.com
References
- http://jvn.jp/en/jp/JVN71256611/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-003557
- http://www.securityfocus.com/bid/51202
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-100
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14815
- http://jvn.jp/en/jp/JVN71256611/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-003557
- http://www.securityfocus.com/bid/51202
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-100
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14815
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.