MS15-041: Vulnerability in .NET Framework Could Allow Information Disclosure (3048010)

Medium Nessus Plugin ID 82777


The version of the Microsoft .NET Framework installed on the remote host is affected by an information disclose vulnerability.


The remote Windows host has a version of the Microsoft .NET Framework installed that is affected by an information disclosure vulnerability due to improper handling of requests on web servers that have custom error messages disabled. A remote, unauthenticated attacker can exploit this issue, via a specially crafted web request, to elicit an error message containing information that was not intended to be accessible.


Microsoft has released a set of patches for .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4.0, 4.5, 4.5.1, and 4.5.2.

See Also

Plugin Details

Severity: Medium

ID: 82777

File Name: smb_nt_ms15-041.nasl

Version: $Revision: 1.5 $

Type: local

Agent: windows

Published: 2015/04/14

Modified: 2017/07/24

Dependencies: 13855, 57033, 51351

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:.net_framework

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2015/04/14

Vulnerability Publication Date: 2015/04/14

Reference Information

CVE: CVE-2015-1648

BID: 74010

OSVDB: 120638

MSFT: MS15-041

MSKB: 3037572, 3037573, 3037574, 3037575, 3037576, 3037577, 3037578, 3037579, 3037580, 3037581

IAVA: 2015-A-0089