Medium severity5.9NVD Advisory· Published Mar 5, 2019· Updated Jun 17, 2026
CVE-2019-0657
CVE-2019-0657
Description
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.NETCore.AppNuGet | >= 2.2.0, < 2.2.2 | 2.2.2 |
Microsoft.NETCore.AppNuGet | >= 2.1.0, < 2.1.8 | 2.1.8 |
System.Private.UriNuGet | >= 4.3.0, < 4.3.2 | 4.3.2 |
Affected products
36cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*+ 22 more
- cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*
- (no CPE)range: Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
- (no CPE)range: Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
- (no CPE)range: Windows Server 2012
- (no CPE)range: Windows 7 for 32-bit Systems Service Pack 1
- (no CPE)range: Windows 7 for 32-bit Systems Service Pack 1
- (no CPE)range: Windows Server 2008 for 32-bit Systems Service Pack 2
- (no CPE)range: Windows Server 2016
- (no CPE)range: Windows 10 for 32-bit Systems
- (no CPE)range: Windows 7 for 32-bit Systems Service Pack 1
- (no CPE)range: Windows 10 Version 1709 for 32-bit Systems
- (no CPE)range: Windows 10 Version 1803 for 32-bit Systems
- (no CPE)range: Windows 10 Version 1703 for 32-bit Systems
cpe:2.3:a:microsoft:powershell_core:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:powershell_core:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:powershell_core:6.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2017:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:visual_studio_2017:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:*
- ghsa-coords2 versions
>= 2.2.0, < 2.2.2+ 1 more
- (no CPE)range: >= 2.2.0, < 2.2.2
- (no CPE)range: >= 4.3.0, < 4.3.2
- Range: 1
- Range: 2017
- Microsoft/Microsoft Visual Studio 2017v5Range: version 15.9
- Range: 6.1
Patches
Vulnerability mechanics
References
7- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657nvdPatchVendor AdvisoryWEB
- www.securityfocus.com/bid/106890nvdThird Party AdvisoryVDB EntryWEB
- access.redhat.com/errata/RHSA-2019:0349nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-x5qj-9vmx-7g6gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-0657ghsaADVISORY
- github.com/dotnet/announcements/issues/97ghsaWEB
- github.com/github/advisory-database/issues/302ghsaWEB
News mentions
0No linked articles in our index yet.