Lucene search

K
kasperskyKaspersky LabKLA10556
HistoryApr 14, 2015 - 12:00 a.m.

KLA10556 Obtain sensitive information vulnerability in .NET Framework

2015-04-1400:00:00
Kaspersky Lab
threats.kaspersky.com
41

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%

An unspecified vulnerability was found in Microsoft .NET. By exploiting this vulnerability malicious users can obtain sensitive information. This vulnerability can be exploited remotely via a specially designed request.

Original advisories

MS15-041

CVE-2015-1648

Related products

Microsoft-Windows-Vista-4

Microsoft-Windows-Server-2012

Microsoft-Windows-8

Microsoft-Windows-7

Microsoft-Windows-Server-2008

Microsoft-Windows-Server-2003

Windows-RT

CVE list

CVE-2015-1648 warning

KB list

3037575

3037574

3037577

3037576

3037573

3037572

3037580

3037581

3037579

3037578

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

Affected Products

  • Microsoft .NET Framework versions 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1 and 4.5.2

References

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%