HTTP: Microsoft .NET Framework Denial of Service

This signature detects attempts to exploit a known vulnerability against Microsoft .NET framework. A successful attack can lead to Denial of service.

Extended Description

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka ".NET Framework Stack Overflow Denial of Service Vulnerability."

Affected Products

Microsoft .net_framework

References

CVE: CVE-2016-0033

Short Name
HTTP:STC:CVE-2016-0033-DOS
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
.NET CVE-2016-0033 Denial Framework Microsoft Service of
Release Date
02/09/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3730
False Positive
Rarely
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?