CVE-2024-21386
published 2024-02-13CVE-2024-21386: .NET Denial of Service Vulnerability .NET Denial of Service Vulnerability
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.40%
82.2th percentile
.NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core_6.0 | >= 6.0 < 6.0.27 | 6.0.27 |
| microsoft | asp.net_core_7.0 | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | asp.net_core_8.0 | >= 8.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 0 < 6.0.27 | 6.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 7.0.0 < 7.0.16 | 7.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.2 | 8.0.2 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 0 < 6.0.27 | 6.0.27 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvelistv57.5HIGH
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET Denial of Service Vulnerability
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
.NET: .NET
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://dotnet.microsoft.com/download/dotnet/6.0
Reference: https://github.com/dotnet/announcements/issues/295
Reference: https://dotnet.microsoft.com/download/dotnet/7.0
Reference: https://dotnet.microsoft.com/download/dotnet/8.0
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.4
Reference: https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
Reference: https://my.visualstud
Red Hat
dotnet: Denial of Service in SignalR server
vendor_redhat·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] dotnet: Denial of Service in SignalR server
dotnet: Denial of Service in SignalR server
.NET Denial of Service Vulnerability
A denial of service vulnerability is present in the .NET applications utilizing SignalR, which a malicious client can exploit. The issue arises from inadequate validation of user-supplied input in .NET. This flaw allows a remote attacker to trigger a denial of service (DoS) attack by providing specially crafted input.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
Brennan Conroy discovered that .NET with SignalR did not properly
handle malicious clients. An attacker could possibly use this issue
to cause a denial of service. (CVE-2024-21386)
Bahaa Naamneh discovered that .NET with OpenSSL support did not
properly parse X509 certificates. An attacker could possibly use
this issue to cause a denial of service. (CVE-2024-21404)
Instructions: In general, a standard system update will make all the necessary changes.
GHSA
Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
ghsa·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] CWE-400 Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-g74q-5xw3-j7q9. This link is maintained to preserve external references.
## Original Description
.NET Denial of Service Vulnerability
CVEList
.NET Denial of Service Vulnerability
cvelistv5·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
OSV
Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
osv·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET 6.0, ASP.NET 7.0 and, ASP.NET 8.0 . This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
A vulnerability exists in ASP.NET applications using SignalR where a malicious client can result in a denial-of-service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/295
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected s
OSV
Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
osv·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-g74q-5xw3-j7q9. This link is maintained to preserve external references.
## Original Description
.NET Denial of Service Vulnerability
GHSA
Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
ghsa·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] CWE-400 Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET 6.0, ASP.NET 7.0 and, ASP.NET 8.0 . This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
A vulnerability exists in ASP.NET applications using SignalR where a malicious client can result in a denial-of-service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/295
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected s
OSV
dotnet6, dotnet7, dotnet8 vulnerabilities
osv·2024-02-13·CVSS 7.5
CVE-2024-21386 [HIGH] dotnet6, dotnet7, dotnet8 vulnerabilities
dotnet6, dotnet7, dotnet8 vulnerabilities
Brennan Conroy discovered that .NET with SignalR did not properly
handle malicious clients. An attacker could possibly use this issue
to cause a denial of service. (CVE-2024-21386)
Bahaa Naamneh discovered that .NET with OpenSSL support did not
properly parse X509 certificates. An attacker could possibly use
this issue to cause a denial of service. (CVE-2024-21404)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
blogs_bleepingcomputer·2024-02-13·CVSS 7.6
[HIGH] Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
## Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
## Lawrence Abrams
16 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
30 Remote Code Execution Vulnerabilities
5 Information Disclosure Vulnerabilities
9 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
The total count of 73 flaws does not include 6 Microsoft Edge flaws fixed on February 8th and 1 Mariner flaw.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034765 cumulative update and the Windows 10 KB5034763 update .
## Two zero-days fixed
This month's Patch Tuesday fixes two actively exploited zero-day vulnerabilities, which Microsoft classifies as a flaw that is publicly disclosed or ac
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs 2024/02/12 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
8.
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12
The February 2024 Security Update Review
# The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs
2024/02/12
Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
Adobe Patches for February 2024
For February, Adobe released six patches addressing 29 CVEs in Adobe Acrobat and Reader, Commerce, Substance 3D
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs Feb 12, 2024 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the February 2024 security update and review.
By: Dustin Childs Feb 12, 2024 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
2024-02-13
Published