ASP.NET Core Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? This vulnerability could be exploited if http requests to .NET 8 RC 1 running on IIS InProcess hosting model are cancelled. Threads counts would increase and an OutOfMemoryException is possible.
According to the CVSS metric, successful exploitation of this vulnerability could lead to a total loss of availability (A:H). What does that mean for this vulnerability? If an attacker was able to successfully exploit the vulnerability the attack might result in a total loss of availability.
🎯 Affected products6
- .NET 8.0
- ASP.NET Core 8.0
- Microsoft Visual Studio 2022 version 17.2
- Microsoft Visual Studio 2022 version 17.4
- Microsoft Visual Studio 2022 version 17.6
- Microsoft Visual Studio 2022 version 17.7
✅ Remediation
KBRelease Notes (Security Update) — fixed build 8.0.0 KBRelease Notes (Security Update) — fixed build 17.2.22 KBRelease Notes (Security Update) — fixed build 17.4.14 KBRelease Notes (Security Update) — fixed build 17.6.10 KBRelease Notes (Security Update) — fixed build 17.7.7
🔗 References (11)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36038
- patchhttps://dotnet.microsoft.com/download/dotnet/8.0
- referencehttps://github.com/dotnet/announcements/issues/52043
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.2
- referencehttps://docs.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.4
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.7
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/8.0
- referencehttps://github.com/dotnet/announcements/issues/286