CVE-2022-21986HighCVSS 7.5

.NET Denial of Service Vulnerability

Published
February 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What .NET component is affected by this denial of service vulnerability? This vulnerability affects applications that utilize the Kestrel web server when processing certain HTTP/2 and HTTP/3 requests.

🎯 Affected products6

  • .NET 5.0
  • .NET 6.0
  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
  • Microsoft Visual Studio 2022 version 17.0
  • Visual Studio 2019 for Mac version 8.10

✅ Remediation

KBRelease Notes (Security Update) — fixed build 16.9.17 KBRelease Notes (Security Update) — fixed build 16.11.10 KBRelease Notes (Security Update) — fixed build 17.0.6 KBRelease Notes (Security Update) — fixed build 8.10.18 KBRelease Notes (Security Update) — fixed build 5.0.14 KBRelease Notes (Security Update) — fixed build 6.0.2

🔗 References (7)