CVE-2019-0545
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 9.61% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/.net framework · microsoft/.net core
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/106405Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0040Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0545Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106405Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0040Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0545Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.