Security Updates for Microsoft .NET Framework (2022 年 11 月)

medium Nessus Plugin ID 167254

概要

遠端主機上安裝的 Microsoft .NET Framework 缺少安全性更新。

說明

遠端主機上安裝的 Microsoft .NET Framework 缺少安全性更新。因此,它受到 System.Data.SqlClient 和 Microsoft.Data.SqlClient 套件中的資訊洩漏弱點影響。在高負載下發生逾時可造成因非同步執行查詢而傳回不正確的資料。

解決方案

Microsoft 已經發佈 Microsoft .NET Framework 適用的安全性更新。

另請參閱

http://www.nessus.org/u?7499964d

http://www.nessus.org/u?893ba2be

https://support.microsoft.com/en-us/help/5020606

https://support.microsoft.com/en-us/help/5020608

https://support.microsoft.com/en-us/help/5020609

https://support.microsoft.com/en-us/help/5020610

https://support.microsoft.com/en-us/help/5020611

https://support.microsoft.com/en-us/help/5020612

https://support.microsoft.com/en-us/help/5020613

https://support.microsoft.com/en-us/help/5020614

https://support.microsoft.com/en-us/help/5020615

https://support.microsoft.com/en-us/help/5020617

https://support.microsoft.com/en-us/help/5020618

https://support.microsoft.com/en-us/help/5020619

https://support.microsoft.com/en-us/help/5020620

https://support.microsoft.com/en-us/help/5020621

https://support.microsoft.com/en-us/help/5020622

https://support.microsoft.com/en-us/help/5020623

https://support.microsoft.com/en-us/help/5020624

https://support.microsoft.com/en-us/help/5020627

https://support.microsoft.com/en-us/help/5020628

https://support.microsoft.com/en-us/help/5020629

https://support.microsoft.com/en-us/help/5020630

https://support.microsoft.com/en-us/help/5020632

Plugin 詳細資訊

嚴重性: Medium

ID: 167254

檔案名稱: smb_nt_ms22_nov_dotnet.nasl

版本: 1.6

類型: local

代理程式: windows

已發布: 2022/11/10

已更新: 2023/10/5

支援的感應器: Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.4

CVSS v2

風險因素: Medium

基本分數: 4.3

時間分數: 3.6

媒介: CVSS2#AV:A/AC:H/Au:S/C:C/I:N/A:N

CVSS 評分資料來源: CVE-2022-41064

CVSS v3

風險因素: Medium

基本分數: 5.8

時間分數: 5.4

媒介: CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

時間媒介: CVSS:3.0/E:F/RL:O/RC:C

弱點資訊

CPE: cpe:/a:microsoft:.net_framework

必要的 KB 項目: SMB/MS_Bulletin_Checks/Possible

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2022/11/8

弱點發布日期: 2022/11/8

參考資訊

CVE: CVE-2022-41064

IAVA: 2022-A-0477-S

MSFT: MS22-5020606, MS22-5020608, MS22-5020609, MS22-5020610, MS22-5020611, MS22-5020612, MS22-5020613, MS22-5020614, MS22-5020615, MS22-5020617, MS22-5020618, MS22-5020619, MS22-5020620, MS22-5020621, MS22-5020622, MS22-5020623, MS22-5020624, MS22-5020627, MS22-5020628, MS22-5020629, MS22-5020630, MS22-5020632

MSKB: 5020606, 5020608, 5020609, 5020610, 5020611, 5020612, 5020613, 5020614, 5020615, 5020617, 5020618, 5020619, 5020620, 5020621, 5020622, 5020623, 5020624, 5020627, 5020628, 5020629, 5020630, 5020632