CVE-2019-0545

MEDIUM

Description

An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.

References

http://www.securityfocus.com/bid/106405

https://access.redhat.com/errata/RHSA-2019:0040

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0545

Details

Source: MITRE

Published: 2019-01-08

Updated: 2019-01-14

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Vulnerable Software

Configuration 1

AND

OR

cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*

Configuration 2

AND

OR

cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

Configuration 3

AND

OR

cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*

cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

Configuration 4

AND

OR

cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Configuration 5

AND

OR

cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*

Configuration 6

AND

OR

cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Configuration 7

AND

OR

cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server:1709:*:*:*:*:*:*:*

Configuration 8

AND

OR

cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server:1803:*:*:*:*:*:*:*

Configuration 9

AND

OR

cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*

Configuration 10

OR

cpe:2.3:a:microsoft:.net_core:2.1:*:*:*:*:*:*:*

cpe:2.3:a:microsoft:.net_core:2.2:*:*:*:*:*:*:*

Tenable Plugins

View all (13 total)

IDNameProductFamilySeverity
123132Security Update for .NET Core (January 2019)NessusWindows
medium
121143RHEL 7 : dotNET (RHSA-2019:0040)NessusRed Hat Local Security Checks
medium
121021Security Updates for Microsoft .NET Framework (January 2019)NessusWindows : Microsoft Bulletins
medium
121020KB4480978: Windows 10 Version 1709 and Windows Server Version 1709 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121019KB4480972: Windows Server 2012 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121018KB4480973: Windows 10 Version 1703 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121017KB4480960: Windows 7 and Windows Server 2008 R2 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121016KB4480957: Windows Server 2008 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121015KB4480966: Windows 10 Version 1803 and Windows Server Version 1803 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121014KB4480964: Windows 8.1 and Windows Server 2012 R2 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121013KB4480962: Windows 10 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121012KB4480961: Windows 10 Version 1607 and Windows Server 2016 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high
121011KB4480116: Windows 10 Version 1809 and Windows Server 2019 January 2019 Security UpdateNessusWindows : Microsoft Bulletins
high