PT-2021-1575 · Microsoft+3 · Visual Studio+5

Published

2021-01-12

·

Updated

2024-10-08

·

CVE-2021-1723

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: ASP.NET Core and Visual Studio (affected versions not specified)
Description: The issue is related to insufficient input validation in ASP.NET Core and Visual Studio, which can lead to a denial-of-service condition. This can be exploited by a remote attacker to cause a service disruption. The vulnerability is specifically related to the way Kestrel parses HTTP/2 requests.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1178
BDU:2021-00192
BIT-ASPNET-CORE-2021-1723
CESA-2021_0094
CESA-2021_0095
CVE-2021-1723
GHSA-242J-2GM6-5RWX
RHSA-2021:0094
RHSA-2021:0095
RHSA-2021:0096
RHSA-2021:0114
RHSA-2021_0094
RHSA-2021_0095

Affected Products

Alt Linux
Asp.Net Core
Centos
Kestrel
Red Hat
Visual Studio