CVE-2017-0248

high
Published 2017-05-12 · Modified 2024-12-05
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2
5.0
VIR risk
7.5

Description

Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secure@microsoft.com — https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0248

Package impact

EcosystemPackageVulnerableFixed
nuget NuGetMicrosoft.AspNetCore.Mvc>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Core>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Core>=1.1.0,<1.1.31.1.3
nuget NuGetSystem.Net.Http>=4.1.1,<4.1.24.1.2
nuget NuGetSystem.Net.Http>=4.3.1,<4.3.24.3.2
nuget NuGetSystem.Text.Encodings.Web>=4.0.0,<4.0.14.0.1
nuget NuGetSystem.Text.Encodings.Web>=4.3.0,<4.3.14.3.1
nuget NuGetSystem.Net.Http.WinHttpHandler>=4.0.0,<4.0.14.0.1
nuget NuGetSystem.Net.Http.WinHttpHandler>=4.3.0,<4.3.14.3.1
nuget NuGetSystem.Net.Security>=4.0.0,<4.0.14.0.1
nuget NuGetSystem.Net.Security>=4.3.0,<4.3.14.3.1
nuget NuGetSystem.Net.WebSockets.Client>=4.0.0,<4.0.14.0.1
nuget NuGetSystem.Net.WebSockets.Client>=4.3.0,<4.3.14.3.1
nuget NuGetMicrosoft.AspNetCore.Mvc.Abstractions>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Abstractions>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.ApiExplorer>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.ApiExplorer>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Cors>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Cors>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.DataAnnotations>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.DataAnnotations>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Formatters.Json>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Formatters.Json>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Formatters.Xml>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Formatters.Xml>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Localization>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Localization>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Razor.Host>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Razor.Host>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.Razor>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.Razor>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.TagHelpers>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.TagHelpers>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.ViewFeatures>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.ViewFeatures>=1.1.0,<1.1.31.1.3
nuget NuGetMicrosoft.AspNetCore.Mvc.WebApiCompatShim>=1.0.0,<1.0.41.0.4
nuget NuGetMicrosoft.AspNetCore.Mvc.WebApiCompatShim>=1.1.0,<1.1.31.1.3

Application impact

VendorProductVersionsFixed
windows microsoft.net_framework2.0
windows microsoft.net_framework3.5
windows microsoft.net_framework3.5.1
windows microsoft.net_framework4.5.2
windows microsoft.net_framework4.6
windows microsoft.net_framework4.6.1
windows microsoft.net_framework4.6.2
windows microsoft.net_framework4.7

References

CWEs

CWE-295

Verify integrity in audit chain (admin only). AS-IS.