Security and Quality Rollup for .NET Framework (April 2017)

high Nessus Plugin ID 99365

Synopsis

The remote Windows host has a software framework installed that is affected by an arbitrary code execution vulnerability.

Description

The version of Microsoft .NET Framework installed on the remote Windows host is missing a security update. It is, therefore, affected by an arbitrary code execution vulnerability due to a failure to properly validate input before loading libraries. A local attacker can exploit this to execute arbitrary code with elevated privileges.

Solution

Microsoft has released a set of patches for Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, and 4.7

See Also

http://www.nessus.org/u?af87bdc8

http://www.nessus.org/u?75fb2a89

Plugin Details

Severity: High

ID: 99365

File Name: smb_nt_ms17_apr_4014981.nasl

Version: 1.14

Type: local

Agent: windows

Published: 4/14/2017

Updated: 9/13/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:.net_framework

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/11/2017

Vulnerability Publication Date: 4/11/2017

Reference Information

CVE: CVE-2017-0160

BID: 97447

MSFT: MS17-4014545, MS17-4014546, MS17-4014547, MS17-4014548, MS17-4014549, MS17-4014550, MS17-4014551, MS17-4014552, MS17-4014553, MS17-4014555, MS17-4014556, MS17-4014557, MS17-4014558, MS17-4014559, MS17-4014560, MS17-4014561, MS17-4014562, MS17-4014563, MS17-4014564, MS17-4014565, MS17-4014566, MS17-4014567, MS17-4014571, MS17-4014572, MS17-4014573, MS17-4014574, MS17-4015217, MS17-4015219, MS17-4015221, MS17-4015583

MSKB: 4014545, 4014546, 4014547, 4014548, 4014549, 4014550, 4014551, 4014552, 4014553, 4014555, 4014556, 4014557, 4014558, 4014559, 4014560, 4014561, 4014562, 4014563, 4014564, 4014565, 4014566, 4014567, 4014571, 4014572, 4014573, 4014574, 4015217, 4015219, 4015221, 4015583