CVE-2022-23267
published 2022-05-10CVE-2022-23267: .NET and Visual Studio Denial of Service Vulnerability
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.04%
91.3th percentile
.NET and Visual Studio Denial of Service Vulnerability
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 5.0.1 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.0.0 < 3.1.25 | 3.1.25 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: excess memory allocation via HttpClient causes DoS
vendor_redhat·2022-05-10·CVSS 7.5
CVE-2022-23267 [HIGH] CWE-770 dotnet: excess memory allocation via HttpClient causes DoS
dotnet: excess memory allocation via HttpClient causes DoS
.NET and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. The Microsoft Security Advisory describes the issue of the Apply MaxResponseHeadersLength limit for trailing headers to address a denial of service via excess memory allocations through the HttpClient.
Statement: Affected .NET versions: 6.0, 5.0, 3.1
Microsoft
.NET and Visual Studio Denial of Service Vulnerability
vendor_msrc·2022-05-10·CVSS 7.5
CVE-2022-23267 [HIGH] .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio: .NET and Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014326
Reference: https://support.microsoft.com/help/5014326
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014329
Reference: https://support.microsoft.com/help/5014329
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.9
Reference: https://docs.microsoft.com/en-us/visualstudio/releases/2019/release-note
OSV
.NET Denial of Service Vulnerability
osv·2022-10-21·CVSS 7.5
CVE-2022-23267 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET Core 3.1 where a malicious client can cause a Denial of Service via excess memory allocations through HttpClient.
### Affected software
* Any .NET 6.0 application running on .NET 6.0.4 or earlier.
* Any .NET 5.0 application running .NET 5.0.16 or earlier.
* Any .NET Core 3.1 applicaiton running on .NET Core 3.1.24 or earlier.
### Patches
* If you're using .NET Core 6.0, you should download and install Runtime 6.0.5 or SDK 6.0.105 (for Visual Stud
GHSA
.NET Denial of Service Vulnerability
ghsa·2022-10-21·CVSS 7.5
CVE-2022-23267 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET Core 3.1 where a malicious client can cause a Denial of Service via excess memory allocations through HttpClient.
### Affected software
* Any .NET 6.0 application running on .NET 6.0.4 or earlier.
* Any .NET 5.0 application running .NET 5.0.16 or earlier.
* Any .NET Core 3.1 applicaiton running on .NET Core 3.1.24 or earlier.
### Patches
* If you're using .NET Core 6.0, you should download and install Runtime 6.0.5 or SDK 6.0.105 (for Visual Stud
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23267https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNXQL7EZORGU4PZCPJ5EPQ4P7IEY3ZZO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IBYSBUDJYQ76HK4TULXVIIPCKK2U6WDB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5FPEQ6BTYRGTS6IYCDTZW6YF5HLQ3BY/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-23267
2022-05-10
Published