PT-2023-4225 · Microsoft+8 · Net+9
CVE-2023-38180
·
Publicado
2023-08-08
·
Atualizado
2026-05-07
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
.NET and Visual Studio versions prior to the fixed version in August 2023 Patch Tuesday
Description
The issue is related to a Denial of Service (DoS) vulnerability in .NET and Visual Studio. It can be exploited for DoS attacks with no user interaction, allowing a remote attacker to cause a denial of service. The vulnerability has been added to the Known Exploited Vulnerabilities catalog due to active exploitation. Microsoft has issued fixes in their August Patch Tuesday.
Recommendations
For .NET and Visual Studio versions prior to the fixed version in August 2023 Patch Tuesday:
Apply the August 2023 Patch Tuesday updates to fix the vulnerability.
As a temporary workaround, consider restricting access to vulnerable components until a patch is available.
Avoid using potentially vulnerable functions or parameters in affected API endpoints until the issue is resolved.
At the moment, there is no information about additional mitigation measures.
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Centos
Linuxmint
Net
Red Hat
Red Os
Rocky Linux
Ubuntu
Visual Studio