CVE-2016-0149

Description

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka TLS/SSL Information Disclosure Vulnerability.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
15.754

Associated Vulnerability

VulnerabilityOS Platform
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3142023) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3142023) x86 based systemsWindows
TLS/SSL Information Disclosure Vulnerability for .NET Framework 4.6.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142037) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for .NET Framework 4.6.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142037)Windows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.6.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142037)Windows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.6 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3142037)Windows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142036) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142036) x86 based systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows Server 2012 (KB3142035)Windows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3156421) - CumulativeWindows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3156421) - CumulativeWindows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3156387) - CumulativeWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142024) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142024)Windows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3142026) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3142026)Windows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3142025)Windows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3142033) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3142033) x86 based systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142030) x64 bases systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142030) x86 based systemsWindows
TLS/SSL Information Disclosure Vulnerability for Microsoft .NET Framework 4.5.2 on Windows Server 2012 (KB3142032)Windows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 (KB3156387)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-20663Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3142023)
PATCH-20662Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3142023)
PATCH-20667Security Update for .NET Framework 4.6.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142037)
PATCH-20669Security Update for Microsoft .NET Framework 4.6.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142037)
PATCH-20677Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142036)
PATCH-20676Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142036)
PATCH-20680Security Update for Microsoft .NET Framework 4.6 and .NET Framework 4.6.1 on Windows Server 2012 (KB3142035)
PATCH-20504Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3156421)
PATCH-20503Cumulative Update for Windows 10 Version 1511 (KB3156421)
PATCH-20502Cumulative Update for Windows 10 for x64-based Systems (KB3156387)
PATCH-20671Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3142024)
PATCH-20673Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3142026)
PATCH-20678Security Update for Microsoft .NET Framework 3.5 on Windows Server 2012 (KB3142025)
PATCH-20665Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3142033)
PATCH-20664Security Update for Microsoft .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3142033)
PATCH-20675Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142030)
PATCH-20674Security Update for Microsoft .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB3142030)
PATCH-20501Cumulative Update for Windows 10 (KB3156387)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234