CVE-2023-36038HighCVSS 8.2

ASP.NET Core Denial of Service Vulnerability

Published
November 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? This vulnerability could be exploited if http requests to .NET 8 RC 1 running on IIS InProcess hosting model are cancelled. Threads counts would increase and an OutOfMemoryException is possible.

According to the CVSS metric, successful exploitation of this vulnerability could lead to a total loss of availability (A:H). What does that mean for this vulnerability? If an attacker was able to successfully exploit the vulnerability the attack might result in a total loss of availability.

🎯 Affected products6

  • .NET 8.0
  • ASP.NET Core 8.0
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.7

✅ Remediation

KBRelease Notes (Security Update) — fixed build 8.0.0 KBRelease Notes (Security Update) — fixed build 17.2.22 KBRelease Notes (Security Update) — fixed build 17.4.14 KBRelease Notes (Security Update) — fixed build 17.6.10 KBRelease Notes (Security Update) — fixed build 17.7.7

🔗 References (11)