Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0981

Опубликовано: 14 мая 2019
Источник: msrc
EPSS Низкий

Описание

.Net Framework and .Net Core Denial of Service Vulnerability

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication.

A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework or .NET Core application.

The update addresses the vulnerability by correcting how .NET Framework or .NET Core web applications handles web requests.

Обновления

ПродуктСтатьяОбновление
.NET Core 1.0
.NET Core 1.1
PowerShell Core 6.1
.NET Core 2.1
.NET Core 2.2
PowerShell Core 6.2
Microsoft .NET Framework 4.7.2 on Windows 10 Version 1803 for 32-bit Systems
Microsoft .NET Framework 4.7.2 on Windows 10 Version 1803 for ARM64-based Systems
Microsoft .NET Framework 4.7.2 on Windows Server 2019 (Server Core installation)
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

Permanent

EPSS

Процентиль: 87%
0.03215
Низкий

Связанные уязвимости

CVSS3: 7.5
redhat
больше 6 лет назад

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.

CVSS3: 7.5
nvd
больше 6 лет назад

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.

CVSS3: 7.5
github
больше 3 лет назад

Denial of service in ASP.NET Core

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость программных платформ .NET Core, Microsoft .NET Framework и расширяемого средства автоматизации PowerShell Core, связанная с ошибками обработки запросов, позволяющая нарушителю вызвать отказ в обслуживании

oracle-oval
около 6 лет назад

ELSA-2019-1259: dotnet security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 87%
0.03215
Низкий