CVE-2019-1301
published 2019-09-11CVE-2019-1301: A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.33%
91.7th percentile
A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_core | — | — |
| microsoft | net_core | — | — |
| microsoft | powershell_core | — | — |
| microsoft | powershell_core | — | — |
| msrc | net_core_2.1 | — | — |
| msrc | net_core_2.2 | — | — |
| msrc | powershell_core_6.1 | — | — |
| msrc | powershell_core_6.2 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
High severity vulnerability that affects System.Management.Automation
osv·2019-09-13·CVSS 7.5
CVE-2019-1301 [HIGH] High severity vulnerability that affects System.Management.Automation
High severity vulnerability that affects System.Management.Automation
# Microsoft Security Advisory CVE-2019-1301: Denial of Service Vulnerability in PowerShell Core
## Executive Summary
A denial of service vulnerability exists when PowerShell Core or .NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a PowerShell Core scripts.
The update addresses the vulnerability by correcting how the .NET Core handles web requests.
System administrators are advised to update PowerShell Core to an unaffected version (see [affected software](#user-content-affected-software).)
## Discussion
Please [open a support question](https://github.com/PowerShell/PowerShell/issues/new?assignees=&labels=Issue-Question&te
GHSA
High severity vulnerability that affects System.Management.Automation
ghsa·2019-09-13·CVSS 7.5
CVE-2019-1301 [HIGH] High severity vulnerability that affects System.Management.Automation
High severity vulnerability that affects System.Management.Automation
# Microsoft Security Advisory CVE-2019-1301: Denial of Service Vulnerability in PowerShell Core
## Executive Summary
A denial of service vulnerability exists when PowerShell Core or .NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a PowerShell Core scripts.
The update addresses the vulnerability by correcting how the .NET Core handles web requests.
System administrators are advised to update PowerShell Core to an unaffected version (see [affected software](#user-content-affected-software).)
## Discussion
Please [open a support question](https://github.com/PowerShell/PowerShell/issues/new?assignees=&labels=Issue-Question&te
Microsoft
.NET Core Denial of Service Vulnerability
vendor_msrc·2019-09-10·CVSS 7.5
CVE-2019-1301 [HIGH] .NET Core Denial of Service Vulnerability
.NET Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists when .NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core application.
The update addresses the vulnerability by correcting how the .NET Core web application handles web requests.
.NET Core: .NET Core
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Softwa
Red Hat
dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
vendor_redhat·2019-09-10·CVSS 7.5
CVE-2019-1301 [HIGH] CWE-20 dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14463 libmodbus: out-of-bounds read in MODBUS_FC_WRITE_MULTIPLE_COILS
bugzilla·2019-11-12·CVSS 9.1
CVE-2019-14463 [CRITICAL] CVE-2019-14463 libmodbus: out-of-bounds read in MODBUS_FC_WRITE_MULTIPLE_COILS
CVE-2019-14463 libmodbus: out-of-bounds read in MODBUS_FC_WRITE_MULTIPLE_COILS
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.
Reference:
https://github.com/stephane/libmodbus/commit/5ccdf5ef79d742640355d1132fa9e2abc7fbaefc
https://libmodbus.org/2019/stable-and-development-releases/
https://lists.fedoraproject.org/archives/list/[email protected]/message/HAGHQFJTJCMYHW553OUWJ3YIJR6PJHB7/
https://lists.fedoraproject.org/archives/list/[email protected]/message/PRAQZXGAZY6UGWZ6CD33QEFLL7AWW233/
Discussion:
Created libmodbus tracking bugs for this issue:
Affects: epel-all [bug 1771385]
Affects: fedora-all [bug 1771384]
---
Th
Bugzilla
CVE-2019-1301 dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
bugzilla·2019-09-10·CVSS 7.5
CVE-2019-1301 [HIGH] CVE-2019-1301 dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
CVE-2019-1301 dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
An error in Socket.ConnectAsync can be exploited by unauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core web application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1301
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2731 https://access.redhat.com/errata/RHSA-2019:2731
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2019:2732 https://access.redhat.com/errata/RHSA-2019:2732
---
This bug is now closed. Further updates for individual products will be reflecte
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days
blogs_trendmicro·2019-09-11·CVSS 8.8
[HIGH] September Patch Tuesday: RDP Vulns and Zero-Days
Exploits & Vulnerabilities
# September Patch Tuesday: RDP Vulns and Zero-Days
Microsoft’s September Patch Tuesday covered a total of 80 CVEs, 17 of which were rated critical.
By: Trend Micro
2019/09/11
Read time: ( words)
Save to Folio
Microsoft’s September Patch Tuesday covered 80 CVEs, 17 of which were rated critical, and included patches for Azure DevOps Server, Chakra Scripting engine, and Microsoft SharePoint. Sixty-two were labeled as important and included patches for Microsoft Excel, Microsoft Edge, and Microsoft Exchange. Only one was rated as moderate.
### Remote desktop vulnerabilities
Continuing the trend from last month, several of the critical patches were for Remote Desktop Clients and are CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 — all Remote Co
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days
blogs_trendmicro·2019-09-11·CVSS 8.8
[HIGH] September Patch Tuesday: RDP Vulns and Zero-Days
# September Patch Tuesday: RDP Vulns and Zero-Days
Microsoft’s September Patch Tuesday covered a total of 80 CVEs, 17 of which were rated critical.
By: Trend Micro
Sep 11, 2019
Read time: ( words)
Save to Folio
Microsoft’s September Patch Tuesday covered 80 CVEs, 17 of which were rated critical, and included patches for Azure DevOps Server, Chakra Scripting engine, and Microsoft SharePoint. Sixty-two were labeled as important and included patches for Microsoft Excel, Microsoft Edge, and Microsoft Exchange. Only one was rated as moderate.
### Remote desktop vulnerabilities
Continuing the trend from last month, several of the critical patches were for Remote Desktop Clients and are CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 — all Remote Code Execution (RCE) vulnera
2019-09-11
Published