Unknown
CVE-2017-0247
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- asp.net model view controller 1.0.0,
- asp.net model view controller 1.0.1,
- asp.net model view controller 1.0.2,
- asp.net model view controller 1.0.3,
- asp.net model view controller 1.1.0,
- asp.net model view controller 1.1.1,
- asp.net model view controller 1.1.2,
- microsoft.aspnetcore.mvc.abstractions 1.0.0,
- microsoft.aspnetcore.mvc.abstractions 1.0.1,
- microsoft.aspnetcore.mvc.abstractions 1.0.2,
- microsoft.aspnetcore.mvc.abstractions 1.0.3,
- microsoft.aspnetcore.mvc.abstractions 1.1.0,
- microsoft.aspnetcore.mvc.abstractions 1.1.1,
- microsoft.aspnetcore.mvc.abstractions 1.1.2,
- microsoft.aspnetcore.mvc.apiexplorer 1.0.0,
- microsoft.aspnetcore.mvc.apiexplorer 1.0.1,
- microsoft.aspnetcore.mvc.apiexplorer 1.0.2,
- microsoft.aspnetcore.mvc.apiexplorer 1.0.3,
- microsoft.aspnetcore.mvc.apiexplorer 1.1.0,
- microsoft.aspnetcore.mvc.apiexplorer 1.1.1,
- microsoft.aspnetcore.mvc.apiexplorer 1.1.2,
- microsoft.aspnetcore.mvc.cors 1.0.0,
- microsoft.aspnetcore.mvc.cors 1.0.1,
- microsoft.aspnetcore.mvc.cors 1.0.2,
- microsoft.aspnetcore.mvc.cors 1.0.3,
- microsoft.aspnetcore.mvc.cors 1.1.0,
- microsoft.aspnetcore.mvc.cors 1.1.1,
- microsoft.aspnetcore.mvc.cors 1.1.2,
- microsoft.aspnetcore.mvc.dataannotations 1.0.0,
- microsoft.aspnetcore.mvc.dataannotations 1.0.1,
- microsoft.aspnetcore.mvc.dataannotations 1.0.2,
- microsoft.aspnetcore.mvc.dataannotations 1.0.3,
- microsoft.aspnetcore.mvc.dataannotations 1.1.0,
- microsoft.aspnetcore.mvc.dataannotations 1.1.1,
- microsoft.aspnetcore.mvc.dataannotations 1.1.2,
- microsoft.aspnetcore.mvc.formatters.json 1.0.0,
- microsoft.aspnetcore.mvc.formatters.json 1.0.1,
- microsoft.aspnetcore.mvc.formatters.json 1.0.2,
- microsoft.aspnetcore.mvc.formatters.json 1.0.3,
- microsoft.aspnetcore.mvc.formatters.json 1.1.0,
- microsoft.aspnetcore.mvc.formatters.json 1.1.1,
- microsoft.aspnetcore.mvc.formatters.json 1.1.2,
- microsoft.aspnetcore.mvc.formatters.xml 1.0.0,
- microsoft.aspnetcore.mvc.formatters.xml 1.0.1,
- microsoft.aspnetcore.mvc.formatters.xml 1.0.2,
- microsoft.aspnetcore.mvc.formatters.xml 1.0.3,
- microsoft.aspnetcore.mvc.formatters.xml 1.1.0,
- microsoft.aspnetcore.mvc.formatters.xml 1.1.1,
- microsoft.aspnetcore.mvc.formatters.xml 1.1.2,
- microsoft.aspnetcore.mvc.localization 1.0.0,
- microsoft.aspnetcore.mvc.localization 1.0.1,
- microsoft.aspnetcore.mvc.localization 1.0.2,
- microsoft.aspnetcore.mvc.localization 1.0.3,
- microsoft.aspnetcore.mvc.localization 1.1.0,
- microsoft.aspnetcore.mvc.localization 1.1.1,
- microsoft.aspnetcore.mvc.localization 1.1.2,
- microsoft.aspnetcore.mvc.razor 1.0.0,
- microsoft.aspnetcore.mvc.razor 1.0.1,
- microsoft.aspnetcore.mvc.razor 1.0.2,
- microsoft.aspnetcore.mvc.razor 1.0.3,
- microsoft.aspnetcore.mvc.razor 1.1.0,
- microsoft.aspnetcore.mvc.razor 1.1.1,
- microsoft.aspnetcore.mvc.razor 1.1.2,
- microsoft.aspnetcore.mvc.razor.host 1.0.0,
- microsoft.aspnetcore.mvc.razor.host 1.0.1,
- microsoft.aspnetcore.mvc.razor.host 1.0.2,
- microsoft.aspnetcore.mvc.razor.host 1.0.3,
- microsoft.aspnetcore.mvc.razor.host 1.1.0,
- microsoft.aspnetcore.mvc.razor.host 1.1.1,
- microsoft.aspnetcore.mvc.razor.host 1.1.2,
- microsoft.aspnetcore.mvc.taghelpers 1.0.0,
- microsoft.aspnetcore.mvc.taghelpers 1.0.1,
- microsoft.aspnetcore.mvc.taghelpers 1.0.2,
- microsoft.aspnetcore.mvc.taghelpers 1.0.3,
- microsoft.aspnetcore.mvc.taghelpers 1.1.0,
- microsoft.aspnetcore.mvc.taghelpers 1.1.1,
- microsoft.aspnetcore.mvc.taghelpers 1.1.2,
- microsoft.aspnetcore.mvc.viewfeatures 1.0.0,
- microsoft.aspnetcore.mvc.viewfeatures 1.0.1,
- microsoft.aspnetcore.mvc.viewfeatures 1.0.2,
- microsoft.aspnetcore.mvc.viewfeatures 1.0.3,
- microsoft.aspnetcore.mvc.viewfeatures 1.1.0,
- microsoft.aspnetcore.mvc.viewfeatures 1.1.1,
- microsoft.aspnetcore.mvc.viewfeatures 1.1.2,
- microsoft.aspnetcore.mvc.webapicompatshim 1.0.0,
- microsoft.aspnetcore.mvc.webapicompatshim 1.0.1,
- microsoft.aspnetcore.mvc.webapicompatshim 1.0.2,
- microsoft.aspnetcore.mvc.webapicompatshim 1.0.3,
- microsoft.aspnetcore.mvc.webapicompatshim 1.1.0,
- microsoft.aspnetcore.mvc.webapicompatshim 1.1.1,
- microsoft.aspnetcore.mvc.webapicompatshim 1.1.2,
- system.net.http 4.1.1,
- system.net.http 4.3.1,
- system.net.http.winhttphandler 4.0.1,
- system.net.http.winhttphandler 4.3.0,
- system.net.security 4.0.0,
- system.net.security 4.3.0,
- system.net.websockets.client 4.0.0,
- system.net.websockets.client 4.3.0,
- system.text.encodings.web 4.0.0,
- system.text.encodings.web 4.3.0
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: