Description
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
E
Unchanged
RL
O
RC
Changed
Affected products
- Microsoft / Microsoft .NET Framework 2.0 Service Pack 22.0.0 – 2.0.50727.8981
- Microsoft / Microsoft .NET Framework 3.0 Service Pack 23.0.0 – 2.0.50727.8981
- Microsoft / Microsoft .NET Framework 3.53.5.0 – 2.0.50727.8981
- Microsoft / Microsoft .NET Framework 3.5.13.5.0 – 2.0.50727.8981
- Microsoft / Microsoft .NET Framework 3.5 AND 4.7.24.7.0 – 4.7.04137.03
- Microsoft / Microsoft .NET Framework 3.5 AND 4.84.8.0 – 4.8.04798.02
- Microsoft / Microsoft .NET Framework 3.5 AND 4.8.14.8.1 – 4.8.1.09320.02
- Microsoft / Microsoft .NET Framework 4.6.24.7.0 – 4.7.04137.03
- Microsoft / Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.24.7.0 – 4.7.04137.03
- Microsoft / Microsoft .NET Framework 4.84.8.0 – 4.8.04798.02
- Microsoft / Microsoft Visual Studio 2022 version 17.1017.10.0 – 17.10.20
- Microsoft / Microsoft Visual Studio 2022 version 17.1217.12.0 – 17.12.13
- Microsoft / Microsoft Visual Studio 2022 version 17.1417.14.0 – 17.14.17
- Microsoft / .NET 8.08.0.0 – 8.0.21
- Microsoft / .NET 9.09.0.0 – 9.0.10