Back

CVE-2018-8540

CRITICAL

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.

Published: Dec 12, 2018 Modified: Jun 17, 2026
CWE-94

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (10)

Vendor Product Version
microsoft .net_framework 3.5
microsoft .net_framework 3.5
microsoft .net_framework 3.5.1
microsoft .net_framework 4.5.2
microsoft .net_framework 4.6.2
microsoft .net_framework 4.6
microsoft .net_framework 4.6.1
microsoft .net_framework 4.7
microsoft .net_framework 4.7.1
microsoft .net_framework 4.7.2

GitHub Security Advisory GHSA-5vvw-jxjx-wg5h

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 22.13%

Top 3% most likely to be exploited

Threat Score 45.8 / 100

Data Sources

NVD EPSS GitHub