Microsoft .NET Framework 的安全更新(2022 年 11 月)

medium Nessus 插件 ID 167254

简介

远程主机上安装的 Microsoft .NET Framework 缺少安全更新。

描述

远程主机上安装的 Microsoft .NET Framework 缺少安全更新。因此,它受到 System.Data.SqlClient 和 Microsoft.Data.SqlClient 程序包中的信息泄露漏洞影响。高负载下发生的超时可造成以异步方式执行的查询返回不正确的数据。

解决方案

Microsoft 已发布用于 Microsoft .NET Framework 的安全更新。

另见

http://www.nessus.org/u?7499964d

http://www.nessus.org/u?893ba2be

https://support.microsoft.com/en-us/help/5020606

https://support.microsoft.com/en-us/help/5020608

https://support.microsoft.com/en-us/help/5020609

https://support.microsoft.com/en-us/help/5020610

https://support.microsoft.com/en-us/help/5020611

https://support.microsoft.com/en-us/help/5020612

https://support.microsoft.com/en-us/help/5020613

https://support.microsoft.com/en-us/help/5020614

https://support.microsoft.com/en-us/help/5020615

https://support.microsoft.com/en-us/help/5020617

https://support.microsoft.com/en-us/help/5020618

https://support.microsoft.com/en-us/help/5020619

https://support.microsoft.com/en-us/help/5020620

https://support.microsoft.com/en-us/help/5020621

https://support.microsoft.com/en-us/help/5020622

https://support.microsoft.com/en-us/help/5020623

https://support.microsoft.com/en-us/help/5020624

https://support.microsoft.com/en-us/help/5020627

https://support.microsoft.com/en-us/help/5020628

https://support.microsoft.com/en-us/help/5020629

https://support.microsoft.com/en-us/help/5020630

https://support.microsoft.com/en-us/help/5020632

插件详情

严重性: Medium

ID: 167254

文件名: smb_nt_ms22_nov_dotnet.nasl

版本: 1.6

类型: local

代理: windows

发布时间: 2022/11/10

最近更新时间: 2023/10/5

支持的传感器: Nessus

风险信息

VPR

风险因素: Medium

分数: 4.4

CVSS v2

风险因素: Medium

基本分数: 4.3

时间分数: 3.6

矢量: CVSS2#AV:A/AC:H/Au:S/C:C/I:N/A:N

CVSS 分数来源: CVE-2022-41064

CVSS v3

风险因素: Medium

基本分数: 5.8

时间分数: 5.4

矢量: CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

时间矢量: CVSS:3.0/E:F/RL:O/RC:C

漏洞信息

CPE: cpe:/a:microsoft:.net_framework

必需的 KB 项: SMB/MS_Bulletin_Checks/Possible

可利用: true

易利用性: Exploits are available

补丁发布日期: 2022/11/8

漏洞发布日期: 2022/11/8

参考资料信息

CVE: CVE-2022-41064

IAVA: 2022-A-0477-S

MSFT: MS22-5020606, MS22-5020608, MS22-5020609, MS22-5020610, MS22-5020611, MS22-5020612, MS22-5020613, MS22-5020614, MS22-5020615, MS22-5020617, MS22-5020618, MS22-5020619, MS22-5020620, MS22-5020621, MS22-5020622, MS22-5020623, MS22-5020624, MS22-5020627, MS22-5020628, MS22-5020629, MS22-5020630, MS22-5020632

MSKB: 5020606, 5020608, 5020609, 5020610, 5020611, 5020612, 5020613, 5020614, 5020615, 5020617, 5020618, 5020619, 5020620, 5020621, 5020622, 5020623, 5020624, 5020627, 5020628, 5020629, 5020630, 5020632