CVE-2016-0033

Description

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka .NET Framework Stack Overflow Denial of Service Vulnerability.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
23.441

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3122646) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3122646) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122656)Windows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122656) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122661) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122661) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3122648) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3122648) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3122651) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3122651) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122654) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122654) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122660) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122660) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3122655)Windows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows Server 2012 (KB3122658)Windows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3127219) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3127219) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127229) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127229) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127233) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127233) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3127220) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3127220) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3127222) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3127222) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127226) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127226) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127231) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127231) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3127221)Windows
Security Update for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3127227)Windows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on oWindows Server 2012 (KB3127230)Windows
Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3122649)Windows
Security Update for Windows 10 for x64-based Systems (KB3135174)Windows
Cumulative Update for Windows 10 Version 1511 (KB3135173)Windows
Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3135173)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-19941Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3122646)
PATCH-19942Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3122646)
PATCH-19944Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122656)
PATCH-19945Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122661)
PATCH-19946Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3122661)
PATCH-19947Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3122648)
PATCH-19948Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3122648)
PATCH-19949Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3122651)
PATCH-19950Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3122651)
PATCH-19951Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1 (KB3122654)
PATCH-19952Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122654)
PATCH-19953Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122660)
PATCH-19954Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3122660)
PATCH-19955Security Update for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3122655)
PATCH-19956Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows Server 2012 (KB3122658)
PATCH-19957Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3127219)
PATCH-19958Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3127219)
PATCH-19959Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127229)
PATCH-19960Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127229)
PATCH-19961Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127233)
PATCH-19962Security Update for Microsoft .NET Framework 4.6 .NET Framework 4.6.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3127233)
PATCH-19963Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3127220)
PATCH-19964Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3127220)
PATCH-19965Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3127222)
PATCH-19966Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3127222)
PATCH-19967Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127226)
PATCH-19968Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127226)
PATCH-19969Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127231)
PATCH-19970Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3127231)
PATCH-19971Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3127221)
PATCH-19972Security Update for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3127227)
PATCH-19973Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on oWindows Server 2012 (KB3127230)
PATCH-19974Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3122649)
PATCH-19983Security Update for Windows 10 for x64-based Systems (KB3135174)
PATCH-19984Cumulative Update for Windows 10 Version 1511 (KB3135173)
PATCH-19985Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3135173)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234