CVE-2022-24464
published 2022-03-09CVE-2022-24464: .NET and Visual Studio Denial of Service Vulnerability
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.31%
87.2th percentile
.NET and Visual Studio Denial of Service Vulnerability
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.0.0 < 3.1.23 | 3.1.23 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: ASP.NET Denial of Service via FormPipeReader
vendor_redhat·2022-03-08·CVSS 7.5
CVE-2022-24464 [HIGH] CWE-1173 dotnet: ASP.NET Denial of Service via FormPipeReader
dotnet: ASP.NET Denial of Service via FormPipeReader
.NET and Visual Studio Denial of Service Vulnerability
A flaw was found in .NET Core, related to the FormPipeReader. This issue allows remote unauthenticated attackers to cause a denial of service.
Microsoft
.NET and Visual Studio Denial of Service Vulnerability
vendor_msrc·2022-03-08·CVSS 7.5
CVE-2022-24464 [HIGH] .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio: .NET and Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://dotnet.microsoft.com/download/dotnet/6.0
Reference: https://github.com/dotnet/announcements/issues/212
Reference: https://dotnet.microsoft.com/download/dotnet/5.0
Reference: https://dotnet.microsoft.com/download/dotnet-core/3.1
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.7
Reference: https://docs.microsoft.com/en-us/visualstudio/releases/2019/release-notes-v16.7
Refe
GHSA
.NET Denial of Service Vulnerability
ghsa·2022-10-21
CVE-2022-24464 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0, and .NET CORE 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Microsoft is aware of a Denial of Service vulnerability, which exists in .NET 6.0, .NET 5.0, and .NET CORE 3.1 when parsing certain types of http form requests.
### Affected Software
* Any .NET 6.0 application running on .NET 6.0.2 or lower
* Any .NET 5.0 application running on .NET 5.0.14 or lower
* Any .NET Core 3.1 application running on .NET Core 3.1.22 or lower
### Patches
To fix the issue, please install the latest version of .NET 6.0 or .NET 5.0 or .NET Core 3.1.. If you have installed one o
OSV
.NET Denial of Service Vulnerability
osv·2022-10-21
CVE-2022-24464 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0, and .NET CORE 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Microsoft is aware of a Denial of Service vulnerability, which exists in .NET 6.0, .NET 5.0, and .NET CORE 3.1 when parsing certain types of http form requests.
### Affected Software
* Any .NET 6.0 application running on .NET 6.0.2 or lower
* Any .NET 5.0 application running on .NET 5.0.14 or lower
* Any .NET Core 3.1 application running on .NET Core 3.1.22 or lower
### Patches
To fix the issue, please install the latest version of .NET 6.0 or .NET 5.0 or .NET Core 3.1.. If you have installed one o
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-09
Published