cbcvebase.
CVE-2023-38178
published 2023-08-08

CVE-2023-38178: .NET Core and Visual Studio Denial of Service Vulnerability

PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.56%
83.4th percentile
.NET Core and Visual Studio Denial of Service Vulnerability

Affected

17 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft.aspnetcore.app.runtime.win-arm>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.aspnetcore.app.runtime.win-arm64>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.aspnetcore.app.runtime.win-x64>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.aspnetcore.app.runtime.win-x86>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.netcore.app.runtime.win-arm>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.netcore.app.runtime.win-arm64>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.netcore.app.runtime.win-x64>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft.netcore.app.runtime.win-x86>= 7.0.0 < 7.0.107.0.10
microsoftmicrosoft_visual_studio_2022_version_17.2>= 17.2.0 < 17.2.1817.2.18
microsoftmicrosoft_visual_studio_2022_version_17.4>= 17.4.0 < 17.4.1017.4.10
microsoftnet
microsoftnet_6.0>= 6.0.0 < 6.0.216.0.21
microsoftvisual_studio_2022>= 17.2.0 < 17.2.1817.2.18
microsoftvisual_studio_2022>= 17.4.0 < 17.4.1017.4.10
msrcmicrosoft_visual_studio_2022_version_17.2
msrcmicrosoft_visual_studio_2022_version_17.4
msrcnet_6.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.