CVE-2023-21722
published 2023-02-14CVE-2023-21722: .NET Framework Denial of Service Vulnerability .NET Framework Denial of Service Vulnerability
medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.92%
56.5th percentile
.NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_2.0_service_pack_2 | >= 2.0.0 < 2.0.50727.8966 | 2.0.50727.8966 |
| microsoft | microsoft_net_framework_3.0_service_pack_2 | >= 3.0.0 < 2.0.50727.8966 | 2.0.50727.8966 |
| microsoft | microsoft_net_framework_3.5 | >= 3.5.0 < 3.5.50727.8966 | 3.5.50727.8966 |
| microsoft | microsoft_net_framework_3.5.1 | >= 3.5.0 < 3.5.50727.8966 | 3.5.50727.8966 |
| microsoft | microsoft_net_framework_3.5_and_4.6.2 | >= 4.7.0 < 10.0.10240.19747 | 10.0.10240.19747 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 10.0.04038.03 | 10.0.04038.03 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 10.0.04614.06 | 10.0.04614.06 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 10.0.09139.02 | 10.0.09139.02 |
| microsoft | microsoft_net_framework_4.6.2 | >= 4.7.0 < 4.7.04038.06 | 4.7.04038.06 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.04614.08 | 4.7.04614.08 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.4614.08 | 4.8.4614.08 |
| msrc | microsoft_net_framework_2.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.5 | — | — |
| msrc | microsoft_net_framework_3.5.1 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.6.2 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.7.2 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.8 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.8.1 | — | — |
| msrc | microsoft_net_framework_4.6.2 | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | — | — |
| msrc | microsoft_net_framework_4.8 | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
cvelistv55.0MEDIUM
vendor_msrc5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
.NET Framework Denial of Service Vulnerability
cvelistv5·2023-02-14·CVSS 5.0
CVE-2023-21722 [MEDIUM] CWE-59 .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
Microsoft
.NET Framework Denial of Service Vulnerability
vendor_msrc·2023-02-14·CVSS 5.0
CVE-2023-21722 [MEDIUM] CWE-59 .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is Denial of Service?
The attack itself is carried out locally. For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website. This could lead to a local attack on the victim's computer which could cause a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published