CVE-2018-8171High
ASP.NET Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated. An attacker who successfully exploited this vulnerability could try an infinite number of authentication attempts. The update addresses the vulnerability by validating the number of incorrect login attempts.
🎯 Affected products7
- ASP.NET Core 1.0
- ASP.NET Core 1.1
- ASP.NET Core 2.0
- ASP.NET MVC 5.2 on Microsoft Visual Studio 2013 Update 5
- ASP.NET MVC 5.2 on Microsoft Visual Studio 2015 Update 3
- ASP.NET Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5
- ASP.NET Web Pages 3.2.3 on Microsoft Visual Studio 2015 Update 3
✅ Remediation
KBCommit (Security Update) KB4339279 (Security Update)