Vulnerability Description
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | .Net Framework | 3.5 |
| Microsoft | Windows 8 | - |
| Microsoft | Windows Server 2012 | - |
| Microsoft | Windows Server 2003 | All versions |
| Microsoft | Windows Server 2008 | All versions |
| Microsoft | Windows Vista | All versions |
| Microsoft | Windows Xp | All versions |
| Microsoft | Windows 7 | All versions |
| Microsoft | Management Odata Iis Extension | - |
Related Weaknesses (CWE)
References
- http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-00
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-00
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2013-0005?
CVE-2013-0005 is a vulnerability with a CVSS score of 7.8 (HIGH). The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, all...
How severe is CVE-2013-0005?
CVE-2013-0005 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0005?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft .Net Framework, Microsoft Windows 8, Microsoft Windows Server 2012, Microsoft Windows Server 2003, Microsoft Windows Server 2008.