CVE-2021-1721
published 2021-02-25CVE-2021-1721: .NET Core and Visual Studio Denial of Service Vulnerability
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.34%
87.8th percentile
.NET Core and Visual Studio Denial of Service Vulnerability
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | opentext_application_automation_tools_plugin | — | — |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 5.0.0 < 5.0.3 | 5.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.12 | 3.1.12 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 5.0.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Denial of service in .NET core
ghsa·2022-05-24
CVE-2021-1721 [MEDIUM] Denial of service in .NET core
Denial of service in .NET core
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
OSV
Denial of service in .NET core
osv·2022-05-24
CVE-2021-1721 [MEDIUM] Denial of service in .NET core
Denial of service in .NET core
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
Microsoft
.NET Core and Visual Studio Denial of Service Vulnerability
vendor_msrc·2021-02-09·CVSS 6.5
CVE-2021-1721 [MEDIUM] .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
Developer Tools: Developer Tools
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.7
Reference: https://github.com/PowerShell/PowerShell#get-powershell
Reference: https://dotnet.microsoft.com/download/dotnet-core/2.1
Reference: https://dotnet.microsoft.com/download/dotnet-core/3.1
Reference: https://dotnet.microsoft.com/download/dotnet/5.0
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.4
Reference: http://aka.ms/vs/16/release/la
Red Hat
dotnet: certificate chain building recursion Denial of Service
vendor_redhat·2021-02-09·CVSS 6.5
CVE-2021-1721 [MEDIUM] CWE-674 dotnet: certificate chain building recursion Denial of Service
dotnet: certificate chain building recursion Denial of Service
.NET Core and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. A recursion error when building X.509 certificate chains can lead to a stack overflow which could crash the system. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
2021-02-25
Published