Executive brief
Microsoft .NET, ASP.NET, and Visual Studio are vulnerable to a denial-of-service attack due to uncontrolled resource consumption. The vulnerability allows an unauthenticated remote attacker to cause a DoS condition via the network.
Affected products
- Microsoft .NET 6.0.0 to 6.0.21, 7.0.0 to 7.0.10
- Microsoft ASP.NET Core 2.1 to 2.1.40
- Microsoft Visual Studio 2022 17.2.0 to 17.2.18, 17.4.0 to 17.4.10, 17.6.0 to 17.6.6
Timeline
- 2023-08-09: disclosed
- 2023-08-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-08-09: patched: Microsoft released patches for affected products.
- exploited: Reported as exploited in the wild.