Summary
This host is missing an important security
update according to Microsoft Bulletin MS14-053.
Impact
Successful exploitation will allow
attackers to cause a denial of service.
Impact Level: Application
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-053
Insight
The flaw is due to an error within
a hash generation function when hashing requests and can be exploited to cause a hash collision resulting in high CPU consumption via specially crafted requests.
Affected
Microsoft .NET Framework 1.1,
2.0, 3.0, 3.5, 3.5.1, 4.0, 4.5, 4.5.1 and 4.5.2
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-4072 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities
- Microsoft AntiXSS Library Information Disclosure Vulnerability (2607664)
- Microsoft Windows Digital Signatures Denial of Service Vulnerability (2868626)
- Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)
- Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554)
- Microsoft IIS Malformed File Extension Denial of Service Vulnerability