CVE-2021-1721
published 2021-02-25CVE-2021-1721: .NET Core and Visual Studio Denial of Service Vulnerability
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.34%
87.3th percentile
.NET Core and Visual Studio Denial of Service Vulnerability
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | opentext_application_automation_tools_plugin | — | — |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 5.0.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Denial of service in .NET core
ghsa·2022-05-24
CVE-2021-1721 [MEDIUM] Denial of service in .NET core
Denial of service in .NET core
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
OSV
Denial of service in .NET core
osv·2022-05-24
CVE-2021-1721 [MEDIUM] Denial of service in .NET core
Denial of service in .NET core
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
Microsoft
.NET Core and Visual Studio Denial of Service Vulnerability
vendor_msrc·2021-02-09·CVSS 6.5
CVE-2021-1721 [MEDIUM] .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
Developer Tools: Developer Tools
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.7
Reference: https://github.com/PowerShell/PowerShell#get-powershell
Reference: https://dotnet.microsoft.com/download/dotnet-core/2.1
Reference: https://dotnet.microsoft.com/download/dotnet-core/3.1
Reference: https://dotnet.microsoft.com/download/dotnet/5.0
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.4
Reference: http://aka.ms/vs/16/release/la
Red Hat
dotnet: certificate chain building recursion Denial of Service
vendor_redhat·2021-02-09·CVSS 6.5
CVE-2021-1721 [MEDIUM] CWE-674 dotnet: certificate chain building recursion Denial of Service
dotnet: certificate chain building recursion Denial of Service
.NET Core and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. A recursion error when building X.509 certificate chains can lead to a stack overflow which could crash the system. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-25
Published