CVE-2017-0248: Microsoft .NET Framework

High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

Affected products

  • Microsoft .NET Framework: version 2.0 only; version 3.5 only; version 3.5.1 only; version 4.5.2 only; version 4.6 only; version 4.6.1 only; …

Published 2017-05-12. Last modified 2026-06-17.