peter bassill · operator
$ cve CVE-2016-0132 JSON

CVE-2016-0132

9.8
CRITICAL · CVSS 3.0 · EPSS 21.5% (pctl 98)

Patch early

EPSS 21.5% — above the 10% action threshold.

Description

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security Feature Bypass."

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS21.47% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2016-03-09
Last modified2026-06-17

Affected (1)

VendorProduct
microsoft.net framework

References

→ the Explorer  ·  watch your stack  ·  NVD