Summary
This host is missing an important security
update according to Microsoft Bulletin MS14-053.
Impact
Successful exploitation will allow
attackers to cause a denial of service.
Impact Level: Application
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-053
Insight
The flaw is due to an error within
a hash generation function when hashing requests and can be exploited to cause a hash collision resulting in high CPU consumption via specially crafted requests.
Affected
Microsoft .NET Framework 1.1,
2.0, 3.0, 3.5, 3.5.1, 4.0, 4.5, 4.5.1 and 4.5.2
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-4072 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities
- Microsoft Host Integration Server Denial of Service Vulnerabilities (2607670)
- Microsoft Remote Desktop Tampering Vulnerability (2969259)
- Microsoft Windows Defender Privilege Elevation Vulnerability (2847927)
- Microsoft Windows IP-HTTPS Component Security Feature Bypass Vulnerability (2765809)
- Microsoft OneNote Information Disclosure Vulnerability (2816264)