CVE-2024-43499
published 2024-11-12CVE-2024-43499: .NET and Visual Studio Denial of Service Vulnerability
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.56%
83.2th percentile
.NET and Visual Studio Denial of Service Vulnerability
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2022_version_17.10 | >= 17.10 < 17.10.9 | 17.10.9 |
| microsoft | microsoft_visual_studio_2022_version_17.11 | >= 17.11 < 17.11.6 | 17.11.6 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.21 | 17.6.21 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.16 | 17.8.16 |
| microsoft | net | — | — |
| microsoft | net_9.0 | >= 9.0.0 < 9.0.0 | 9.0.0 |
| microsoft | powershell_7.5 | >= 7.5.0 < 7.5.0 | 7.5.0 |
| microsoft | visual_studio_2022 | 17.10.0 – 17.10.9 | — |
| microsoft | visual_studio_2022 | >= 17.11.0 < 17.11.6 | 17.11.6 |
| microsoft | visual_studio_2022 | >= 17.6 < 17.6.21 | 17.6.21 |
| microsoft | visual_studio_2022 | >= 17.8 < 17.8.16 | 17.8.16 |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.6 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
| msrc | net_9.0_installed_on_linux | — | — |
| msrc | net_9.0_installed_on_mac_os | — | — |
| msrc | net_9.0_installed_on_windows | — | — |
| msrc | powershell_7.5_installed_on_linux | — | — |
| msrc | powershell_7.5_installed_on_macos | — | — |
| msrc | powershell_7.5_installed_on_windows | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: .NET Core - DoS - (unbounded work factor) in NrbfDecoder component
vendor_redhat·2024-11-12·CVSS 7.5
CVE-2024-43499 [HIGH] dotnet: .NET Core - DoS - (unbounded work factor) in NrbfDecoder component
dotnet: .NET Core - DoS - (unbounded work factor) in NrbfDecoder component
.NET and Visual Studio Denial of Service Vulnerability
A vulnerability was found in .NET. Specifically .NET 9.0 Core - DoS - (unbounded work factor) in NrbfDecoder component
Statement: Red Hat has the information for this vulnerability and its limitation to only .NET Core 9.0. No other versions are expected to be vulnerable to this flaw.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: dotnet8.0 (Red Hat Enterprise Linux 10) - Not affected
Package: dotnet9.0 (Red Hat Enterprise Linux 10) - Not affected
Pack
Microsoft
.NET and Visual Studio Denial of Service Vulnerability
vendor_msrc·2024-11-12·CVSS 7.5
CVE-2024-43499 [HIGH] CWE-409 .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio: .NET and Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
Reference: https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.11
Remediation: Releae Notes
Reference: https://github.com/Power
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2024-11-12·CVSS 9.8
CVE-2024-43499 [CRITICAL] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that the NrbfDecoder component in .NET did not properly
handle an instance of a type confusion vulnerability. An authenticated
attacker could possibly use this issue to gain the privileges of another
user and execute arbitrary code. (CVE-2024-43498)
It was discovered that the NrbfDecoder component in .NET did not properly
perform input validation. An unauthenticated remote attacker could possibly
use this issue to cause a denial of service. (CVE-2024-43499)
Instructions: In general, a standard system update will make all the necessary changes.
OSV
dotnet9 vulnerabilities
osv·2024-11-12·CVSS 9.8
CVE-2024-43498 [CRITICAL] dotnet9 vulnerabilities
dotnet9 vulnerabilities
It was discovered that the NrbfDecoder component in .NET did not properly
handle an instance of a type confusion vulnerability. An authenticated
attacker could possibly use this issue to gain the privileges of another
user and execute arbitrary code. (CVE-2024-43498)
It was discovered that the NrbfDecoder component in .NET did not properly
perform input validation. An unauthenticated remote attacker could possibly
use this issue to cause a denial of service. (CVE-2024-43499)
GHSA
.NET Denial of Service Vulnerability
ghsa·2024-11-12·CVSS 7.5
CVE-2024-43499 [HIGH] CWE-409 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2024-43499 | .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
The NrbfDecoder component in .NET 9 contains a denial of service vulnerability due to incorrect input validation.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/333
## Mitigation factors
Applications that do not use the NrbfDecoder component are not affected by this vulnerability. By default, .NET console apps and web apps do not reference this component.
## A
OSV
CVE-2024-43499
osv·2024-11-12·CVSS 7.5
CVE-2024-43499 [HIGH] CVE-2024-43499
.NET and Visual Studio Denial of Service Vulnerability
OSV
.NET Denial of Service Vulnerability
osv·2024-11-12·CVSS 7.5
CVE-2024-43499 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2024-43499 | .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
The NrbfDecoder component in .NET 9 contains a denial of service vulnerability due to incorrect input validation.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/333
## Mitigation factors
Applications that do not use the NrbfDecoder component are not affected by this vulnerability. By default, .NET console apps and web apps do not reference this component.
## A
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-43499 dotnet: .NET Core - DoS - (unbounded work factor) in NrbfDecoder component
bugzilla·2024-11-01·CVSS 7.5
CVE-2024-43499 [HIGH] CVE-2024-43499 dotnet: .NET Core - DoS - (unbounded work factor) in NrbfDecoder component
CVE-2024-43499 dotnet: .NET Core - DoS - (unbounded work factor) in NrbfDecoder component
.NET Core - DoS - (unbounded work factor) in NrbfDecoder component
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9543 https://access.redhat.com/errata/RHSA-2024:9543
Bleepingcomputer
Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws
blogs_bleepingcomputer·2024-11-12·CVSS 6.5
[MEDIUM] Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws
## Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws
## Lawrence Abrams
26 Elevation of Privilege vulnerabilities
2 Security Feature Bypass vulnerabilities
52 Remote Code Execution vulnerabilities
1 Information Disclosure vulnerability
4 Denial of Service vulnerabilities
3 Spoofing vulnerabilities
This count does not include two Edge flaws that were previously fixed on November 7th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5046617 and KB5046633 cumulative updates and the Windows 10 KB5046613 update .
## Four zero-days disclosed
This month's Patch Tuesday fixes four zero-days, two of which were actively exploited in attacks, and three were publicly disclosed.
Microsoft classifies a
2024-11-12
Published