CVE-2020-1469: Bond Denial of Service Vulnerability

Overview

Severity
N/A
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Jul
Released
2020-07-14
EPSS Score
6.19% (percentile: 90.9%)

Description

A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input. An attacker who successfully exploited the vulnerability could cause a process using Bond to stop responding. To exploit this vulnerability, an attacker would need to upload specially crafted content to a Bond parser. The update addresses the vulnerability by correcting the way Bond processes input.

FAQ

Which versions of Bond contain the vulnerability? All previously released versions of Bond are vulnerable. This includes the first version release 3.x through 9.0. The update is in Bond 9.0.1.

Affected Products (1)

Open Source Software

  • Bond 9.0.1

Security Updates (1)

Acknowledgments

Ben Haham Hay, Microsoft Defender ATP Client Team

Revision History

  • 2020-07-14: Information published.