CVE-2022-21986HighCVSS 7.5
.NET Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What .NET component is affected by this denial of service vulnerability? This vulnerability affects applications that utilize the Kestrel web server when processing certain HTTP/2 and HTTP/3 requests.
🎯 Affected products6
- .NET 5.0
- .NET 6.0
- Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
- Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
- Microsoft Visual Studio 2022 version 17.0
- Visual Studio 2019 for Mac version 8.10
✅ Remediation
KBRelease Notes (Security Update) — fixed build 16.9.17 KBRelease Notes (Security Update) — fixed build 16.11.10 KBRelease Notes (Security Update) — fixed build 17.0.6 KBRelease Notes (Security Update) — fixed build 8.10.18 KBRelease Notes (Security Update) — fixed build 5.0.14 KBRelease Notes (Security Update) — fixed build 6.0.2
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21986
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.9
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.11
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.0
- patchhttps://visualstudio.microsoft.com/vs/mac/
- patchhttps://dotnet.microsoft.com/download/dotnet/5.0
- patchhttps://dotnet.microsoft.com/download/dotnet/6.0