CVE-2007-0042 is a critical vulnerability affecting Microsoft .NET Framework versions 1.0, 1.1, and 2.0 across various Windows operating systems, including 2000, XP, Server 2003, and Vista. This "Null Byte Termination Vulnerability" stems from an interpretation conflict where %00 characters are treated as string terminators by POSIX functions but as data characters by .NET, allowing remote attackers to access configuration files and obtain sensitive information. With a CVSS score of 7.8 (High), it presents a network-based, low-complexity attack that can lead to complete confidentiality compromise without authentication. While not listed in CISA KEV and showing no active community discussion or media coverage, exploit code for null byte injection in .NET Framework 2.0 is publicly available on ExploitDB, indicating a potential for exploitation despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:1.0:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.