| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. |
| An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.
To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.
The update addresses the vulnerability by correcting how .NET Framework activates COM objects. |
| .NET and Visual Studio Remote Code Execution Vulnerability |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. |
| Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. |
| Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. |
| The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| .NET Denial of Service Vulnerability |
| Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability |
| .NET and Visual Studio Denial of Service Vulnerability |