CVE-2016-0132

Description

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka .NET XML Validation Security Feature Bypass.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
32.646

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Update for Windows 10 for x64-based Systems (KB3140745)Windows
Cumulative Update for Windows 10 Version 1511 (KB3140768)Windows
Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3140768)Windows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135983) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135983) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135988) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135988) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.6 (KB3136000) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.6 (KB3136000) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3135982) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3135982) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135985) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135985) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135991)Windows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135991) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3135994)Windows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3135994) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2Windows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3135998)Windows
Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3135984)Windows
Security Update for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3135995)Windows
Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows Server 2012 (KB3135997)Windows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3135987) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3135987) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3135996)Windows
Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3135996) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3135989)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-20152Cumulative Update for Windows 10 for x64-based Systems (KB3140745)
PATCH-20153Cumulative Update for Windows 10 Version 1511 (KB3140768)
PATCH-20154Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3140768)
PATCH-20284Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135983)
PATCH-20285Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135983)
PATCH-20286Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135988)
PATCH-20287Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3135988)
PATCH-20288Security Update for Microsoft .NET Framework 4.6 (KB3136000)
PATCH-20289Security Update for Microsoft .NET Framework 4.6 (KB3136000)
PATCH-20291Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3135982)
PATCH-20292Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135985)
PATCH-20293Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135985)
PATCH-20295Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3135991)
PATCH-20297Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3135994)
PATCH-20298Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2
PATCH-20299Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3135998)
PATCH-20300Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3135984)
PATCH-20301Security Update for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3135995)
PATCH-20302Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows Server 2012 (KB3135997)
PATCH-20306Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3135996)
PATCH-20307Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3135989)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234