HTTP: Microsoft .NET Framework CVE-2015-6115 ASLR Security Bypass

This signature detects an attempt to exploit a known vulnerability against Microsoft .NET Framework. Successful attack could be used to bypass the ASLR security protection for other code execution attacks.

Extended Description

Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka ".NET ASLR Bypass."

Affected Products

Microsoft .net_framework

Short Name
HTTP:STC:DL:MS-NET-ASLR-BYPASS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
.NET ASLR Bypass CVE-2015-6115 Framework Microsoft Security
Release Date
12/18/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

4.3

Found a potential security threat?