PT-2023-4225 · Microsoft+8 · Net+9

Published

2023-08-08

·

Updated

2026-05-07

·

CVE-2023-38180

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions .NET and Visual Studio versions prior to the fixed version in August 2023 Patch Tuesday
Description The issue is related to a Denial of Service (DoS) vulnerability in .NET and Visual Studio. It can be exploited for DoS attacks with no user interaction, allowing a remote attacker to cause a denial of service. The vulnerability has been added to the Known Exploited Vulnerabilities catalog due to active exploitation. Microsoft has issued fixes in their August Patch Tuesday.
Recommendations For .NET and Visual Studio versions prior to the fixed version in August 2023 Patch Tuesday: Apply the August 2023 Patch Tuesday updates to fix the vulnerability. As a temporary workaround, consider restricting access to vulnerable components until a patch is available. Avoid using potentially vulnerable functions or parameters in affected API endpoints until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:4642
ALSA-2023:4643
ALSA-2023:4644
ALSA-2023:4645
ALSA-2023_4642
ALSA-2023_4643
ALSA-2023_4644
ALSA-2023_4645
ALT-PU-2024-1066
ALT-PU-2024-1067
ALT-PU-2024-1068
ALT-PU-2024-1069
ALT-PU-2024-16792
ALT-PU-2024-16794
ALT-PU-2024-16796
ALT-PU-2024-16939
ALT-PU-2024-2761
ALT-PU-2024-2763
ALT-PU-2024-2765
ALT-PU-2024-2767
BDU:2023-04540
BIT-ASPNET-CORE-2023-38180
BIT-DOTNET-2023-38180
BIT-DOTNET-SDK-2023-38180
CESA-2023_4643
CESA-2023_4645
CVE-2023-38180
ELSA-2023-4642
ELSA-2023-4643
ELSA-2023-4644
ELSA-2023-4645
GHSA-VMCH-3W2X-VHGQ
RHSA-2023:4639
RHSA-2023:4640
RHSA-2023:4641
RHSA-2023:4642
RHSA-2023:4643
RHSA-2023:4644
RHSA-2023:4645
RHSA-2023_4642
RHSA-2023_4643
RHSA-2023_4644
RHSA-2023_4645
RLSA-2023:4643
RLSA-2023:4645
RLSA-2023_4643
RLSA-2023_4645
USN-6278-1
USN-6278-2

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Net
Red Hat
Red Os
Rocky Linux
Ubuntu
Visual Studio