CVE-2016-0132
Last modified
CVE-2016-0132 is a vulnerability of currently unknown severity. Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security Feature Bypass.". EPSS estimates a 21.98% chance of exploitation in the next 30 days.
Description
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security Feature Bypass."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | .Net Framework | 2.0 | Sp2 |
| Microsoft | .Net Framework | 3.0 | Sp2 |
| Microsoft | .Net Framework | 3.5 | — |
| Microsoft | .Net Framework | 3.5.1 | — |
| Microsoft | .Net Framework | 4.5.2 | — |
| Microsoft | .Net Framework | 4.6 | — |
| Microsoft | .Net Framework | 4.6.1 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-0132?
How severe is CVE-2016-0132?
How do I fix CVE-2016-0132?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-0126Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remo…
- CVE-2016-0127Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Wor…
- CVE-2016-0128The SAM and LSAD protocol implementations in Microsoft Windo…6.8
- CVE-2016-0129Microsoft Edge allows remote attackers to execute arbitrary …
- CVE-2016-0130Microsoft Edge allows remote attackers to execute arbitrary …
- CVE-2016-0131Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-0133The USB Mass Storage Class driver in Microsoft Windows Vista…
- CVE-2016-0134Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Wor…
- CVE-2016-0135The Secondary Logon Service in Microsoft Windows 10 Gold and…
- CVE-2016-0136Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibili…
- CVE-2016-0137The Click-to-Run (C2R) implementation in Microsoft Office 20…
- CVE-2016-0138Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013…
Are you affected by CVE-2016-0132?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
