CVE-2020-1161
published 2020-05-21CVE-2020-1161: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.70%
92.2th percentile
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft_visual_studio_2017_version_15.9 | — | — |
| microsoft | microsoft_visual_studio_2019 | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.4 | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.5 | — | — |
| microsoft | visual_studio_2017 | 15.1 – 15.9 | — |
| microsoft | visual_studio_2019 | 16.0 – 16.5 | — |
| msrc | asp.net_core_3.1 | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.0 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.5 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ASP.NET Core Denial of Service Vulnerability
osv·2022-05-24
CVE-2020-1161 [HIGH] ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
GHSA
ASP.NET Core Denial of Service Vulnerability
ghsa·2022-05-24
CVE-2020-1161 [HIGH] CWE-20 ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Microsoft
ASP.NET Core Denial of Service Vulnerability
vendor_msrc·2020-05-12·CVSS 7.5
CVE-2020-1161 [HIGH] ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application.
The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
.NET Core: .NET Core
Issuing CNA: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Ex
Red Hat
dotnet: Denial of service due to infinite loop
vendor_redhat·2020-05-12·CVSS 7.5
CVE-2020-1161 [HIGH] CWE-400 dotnet: Denial of service due to infinite loop
dotnet: Denial of service due to infinite loop
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
An infinite loop was found in the HTTP Routing component of Microsoft.AspNetCore.App, which could be exploited by a remote, unauthenticated attacker. This flaw allows an attacker without special privileges to send crafted requests to a machine running an ASP.NET Core application, triggering the infinite loop and causing a denial of service in that application, for example, a web server.
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet3.0 (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1161 dotnet: Denial of service due to infinite loop
bugzilla·2020-04-24·CVSS 7.5
CVE-2020-1161 [HIGH] CVE-2020-1161 dotnet: Denial of service due to infinite loop
CVE-2020-1161 dotnet: Denial of service due to infinite loop
A vulnerability related to handling web requests has been reported in ASP.NET Core. A remote, unauthenticated attacker can exploit this vulnerability to cause a Denial of Service by sending specially crafted requests to a ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1161
---
Acknowledgments:
Name: Microsoft
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:2249 https://access.redhat.com/errata/RHSA-2020:2249
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:2250 https://access.redhat.com/errata/RHSA-2020:2250
---
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901 , a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provi
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
CVE-2020-0901 [CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901, a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the full Snort rule
2020-05-21
Published