Summary
This host is missing an important security
update according to Microsoft Bulletin MS14-053.
Impact
Successful exploitation will allow
attackers to cause a denial of service.
Impact Level: Application
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-053
Insight
The flaw is due to an error within
a hash generation function when hashing requests and can be exploited to cause a hash collision resulting in high CPU consumption via specially crafted requests.
Affected
Microsoft .NET Framework 1.1,
2.0, 3.0, 3.5, 3.5.1, 4.0, 4.5, 4.5.1 and 4.5.2
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-4072 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities
- Flaw in Certificate Enrollment Control (Q323172)
- Microsoft SharePoint Foundation HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
- Exchange 2000 Exhaust CPU Resources (Q320436)
- Microsoft Graphics Component Information Disclosure Vulnerability (3029944)