PT-2026-32880 · Microsoft+4 · .Net Framework+6
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
System.Security.Cryptography.Xml versions 10.0.0 through 10.0.5
System.Security.Cryptography.Xml versions 9.0.0 through 9.0.14
System.Security.Cryptography.Xml versions 8.0.0 through 8.0.2
.NET (affected versions not specified)
.NET Framework (affected versions not specified)
Visual Studio (affected versions not specified)
Description
An issue exists in the
EncryptedXml class where an unauthorized attacker can cause an infinite loop, which is a loop with an unreachable exit condition. This can be exploited over a network to perform a Denial of Service attack, causing the system to become unavailable.Recommendations
Update System.Security.Cryptography.Xml versions 10.0.0 through 10.0.5 to version 10.0.6.
Update System.Security.Cryptography.Xml versions 9.0.0 through 9.0.14 to version 9.0.15.
Update System.Security.Cryptography.Xml versions 8.0.0 through 8.0.2 to version 8.0.3.
Fix
DoS
Infinite Loop
XML Entity Expansion
RCE
Use After Free
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
.Net Framework
Linuxmint
Red Os
Rocky Linux
System.Security.Cryptography.Xml
Ubuntu
Visual Studio