Junglewise Threat Intelligence

CVE-2023-38180: .NET Denial of Service Vulnerability

CVE-2023-38180 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2023-08-09

Technologies: Microsoft Visual Studio 2022, Microsoft Visual Studio, Microsoft Asp.Net Core, Microsoft .NET Core. Vendors: Microsoft.

Executive brief

Microsoft .NET, ASP.NET, and Visual Studio are vulnerable to a denial-of-service attack due to uncontrolled resource consumption. The vulnerability allows an unauthenticated remote attacker to cause a DoS condition via the network.

Affected products

  • Microsoft .NET 6.0.0 to 6.0.21, 7.0.0 to 7.0.10
  • Microsoft ASP.NET Core 2.1 to 2.1.40
  • Microsoft Visual Studio 2022 17.2.0 to 17.2.18, 17.4.0 to 17.4.10, 17.6.0 to 17.6.6

Timeline

  • 2023-08-09: disclosed
  • 2023-08-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-08-09: patched: Microsoft released patches for affected products.
  • exploited: Reported as exploited in the wild.

Related threats