CVE-2021-26423
published 2021-08-12CVE-2021-26423: .NET Core and Visual Studio Denial of Service Vulnerability
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.86%
89.0th percentile
.NET Core and Visual Studio Denial of Service Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.18 | 3.1.18 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 5.0.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft_visual_studio_2017_version_15.9 | >= 15.9.0 < 15.9.38 | 15.9.38 |
| microsoft | microsoft_visual_studio_2019_version_16.10 | >= 16.10.0 < 16.10.5 | 16.10.5 |
| microsoft | microsoft_visual_studio_2019_version_16.4 | >= 16.0 < 16.4.25 | 16.4.25 |
| microsoft | microsoft_visual_studio_2019_version_16.7 | >= 16.0.0 < 16.7.18 | 16.7.18 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: ASP.NET Core WebSocket frame processing DoS
vendor_redhat·2021-08-10·CVSS 7.5
CVE-2021-26423 [HIGH] CWE-835 dotnet: ASP.NET Core WebSocket frame processing DoS
dotnet: ASP.NET Core WebSocket frame processing DoS
.NET Core and Visual Studio Denial of Service Vulnerability
An infinite loop error was found in ASP.NET when processing WebSocket frames. The exploitation of this issue can cause high CPU resource consumption. The highest threat from this vulnerability is to system availability.
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
Microsoft
.NET Core and Visual Studio Denial of Service Vulnerability
vendor_msrc·2021-08-10·CVSS 7.5
CVE-2021-26423 [HIGH] .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
.NET Core & Visual Studio: .NET Core & Visual Studio
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: http://aka.ms/vs/15/release/latest
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.4
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.7
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.9
Reference: http://aka.ms/vs/16/release/latest
Reference: https://visualstudio.microsoft.com/vs/mac/
Reference: https://dotnet.microsoft.com/download/d
OSV
.NET Core Elevation of Privilege Vulnerability
osv·2022-10-25·CVSS 7.5
CVE-2021-26423 [HIGH] .NET Core Elevation of Privilege Vulnerability
.NET Core Elevation of Privilege Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 where .NET (Core) server applications providing WebSocket endpoints could be tricked into endlessly looping while trying to read a single WebSocket frame.
### Patches
* If you're using .NET 5.0, you should download and install Runtime 5.0.9 or SDK 5.0.206 (for Visual Studio 2019 v16.8) or SDK 5.0.303 (for Visual Studio 2019 V16.10) from https://dotnet.microsoft.com/download/dotnet-core/5.0.
* If you're using .NET C
GHSA
.NET Core Elevation of Privilege Vulnerability
ghsa·2022-10-25·CVSS 7.5
CVE-2021-26423 [HIGH] .NET Core Elevation of Privilege Vulnerability
.NET Core Elevation of Privilege Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 where .NET (Core) server applications providing WebSocket endpoints could be tricked into endlessly looping while trying to read a single WebSocket frame.
### Patches
* If you're using .NET 5.0, you should download and install Runtime 5.0.9 or SDK 5.0.206 (for Visual Studio 2019 v16.8) or SDK 5.0.303 (for Visual Studio 2019 V16.10) from https://dotnet.microsoft.com/download/dotnet-core/5.0.
* If you're using .NET C
No detection rules found.
No public exploits indexed.
2021-08-12
Published