Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-1108

Опубликовано: 14 мая 2020
Источник: msrc
EPSS Низкий

Описание

.NET Core & .NET Framework Denial of Service Vulnerability

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication.

A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.

The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.

Обновления

ПродуктСтатьяОбновление
.NET Core 2.1
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
PowerShell Core 6.2
Microsoft Visual Studio 2019 version 16.0
Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
.NET Core 3.1
PowerShell 7.0
Microsoft Visual Studio 2019 version 16.5
.NET 5.0
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 88%
0.03788
Низкий

Связанные уязвимости

CVSS3: 7.5
redhat
больше 5 лет назад

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

CVSS3: 7.5
nvd
больше 5 лет назад

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

CVSS3: 7.5
github
больше 3 лет назад

.NET Core & .NET Framework Denial of Service Vulnerability

oracle-oval
больше 5 лет назад

ELSA-2020-2471: .NET Core on Red Hat Enterprise Linux 8 security update (IMPORTANT)

oracle-oval
больше 5 лет назад

ELSA-2020-2450: .NET Core 3.1 on Red Hat Enterprise Linux 8 security update (IMPORTANT)

EPSS

Процентиль: 88%
0.03788
Низкий