CVE-2018-8171High

ASP.NET Security Feature Bypass Vulnerability

Published
July 10, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated. An attacker who successfully exploited this vulnerability could try an infinite number of authentication attempts. The update addresses the vulnerability by validating the number of incorrect login attempts.

🎯 Affected products7

  • ASP.NET Core 1.0
  • ASP.NET Core 1.1
  • ASP.NET Core 2.0
  • ASP.NET MVC 5.2 on Microsoft Visual Studio 2013 Update 5
  • ASP.NET MVC 5.2 on Microsoft Visual Studio 2015 Update 3
  • ASP.NET Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5
  • ASP.NET Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3

✅ Remediation

KBCommit (Security Update) KB4339279 (Security Update)

🔗 References (3)