.NET Framework Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the privileges required is none (PR:N). What does that mean for this vulnerability? The score is based on websites/apps that are configured to allow anonymous access without authentication. When multiple attack vectors can be used, we assign a score based on the scenario with the higher risk.
🎯 Affected products55
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems
- +25 more not shown
✅ Remediation
KB5033920 (Security Update) — fixed build 4.8.09214.01 KB5033910 (Security Update) — fixed build 4.8.04690.02 KB5034278 (Monthly Rollup) — fixed build 4.8.04690.02 KB5034279 (Monthly Rollup) — fixed build 4.8.04690.02 KB5034273 (Security Update) — fixed build 4.8.04690.02 KB5034272 (Security Update) — fixed build 4.8.04690.02 KB5034276 (Security Update) — fixed build 4.8.04690.02 KB5034274 (Security Update) — fixed build 4.8.04690.02 KB5034275 (Security Update) — fixed build 4.8.04690.02 KB5034273 (Security Update) — fixed build 4.7.04081.03 KB5034119 (Security Update) — fixed build 10.0.14393.6614 KB5034269 (Security Only) — fixed build 4.7.04081.02 KB5034278 (Monthly Rollup) — fixed build 4.7.04081.03 KB5034279 (Monthly Rollup) — fixed build 3.0.50727.8976 KB5034272 (Security Update) — fixed build 4.8.09214.01 KB5034276 (Security Update) — fixed build 4.8.09214.01 KB5034274 (Security Update) — fixed build 4.8.09214.01 KB5034275 (Security Update) — fixed build 4.8.09214.01 KB5034278 (Monthly Rollup) — fixed build 3.0.50727.8976
🔗 References (29)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21312
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033920
- referencehttps://support.microsoft.com/help/5033920
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033910
- referencehttps://support.microsoft.com/help/5033910
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033913
- referencehttps://support.microsoft.com/help/5034278
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033915
- referencehttps://support.microsoft.com/help/5034279
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033911
- referencehttps://support.microsoft.com/help/5034273
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033914
- referencehttps://support.microsoft.com/help/5034272
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033912
- referencehttps://support.microsoft.com/help/5034276
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033909
- referencehttps://support.microsoft.com/help/5034274
- referencehttps://support.microsoft.com/help/5034275
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033904
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5034119
- referencehttps://support.microsoft.com/help/5034119
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033947
- referencehttps://support.microsoft.com/help/5034269
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033905
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033900
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033922
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033919
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033918
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033897