CVE-2018-0764: Microsoft .net Core
High severity, CVSS 7.5. EPSS: 8.9% chance of exploitation in the next 30 days.
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.
Affected products
- Microsoft .net Core: version 1.0 only; version 1.1 only; version 2.0 only
- Microsoft .NET Framework: version 2.0 only; version 3.0 only; version 3.5 only; version 3.5.1 only; version 4.5.2 only; version 4.6 only; …
- Microsoft PowerShell Core: version 6.0 only
Published 2018-01-10. Last modified 2026-06-17.