CVE-2022-29117
.NET and Visual Studio Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
.NET and Visual Studio Denial of Service Vulnerability
Una vulnerabilidad de DenegaciĆ³n de Servicio en .NET y Visual Studio. Este ID de CVE es diferente de CVE-2022-23267, CVE-2022-29145
A flaw was found in dotnet. The Microsoft Security Advisory describes the issue of a malicious client that can send MyCookie=chunks-2147483647 without the actual cookie chunks, causing large allocations, exceptions, and excess CPU utilization on the server when it tries to read or delete that many chunks.
.NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET Core that address a security vulnerability are now available. The updated versions are .NET Core SDK 5.0.214 and .NET Core Runtime 5.0.17. Issues addressed include a denial of service vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-12 CVE Reserved
- 2022-05-10 CVE Published
- 2025-01-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-565: Reliance on Cookies without Validation and Integrity Checking
CAPEC
References (7)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-29117 | 2023-12-21 |
URL | Date | SRC |
---|---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29117 | 2025-01-02 | |
https://access.redhat.com/security/cve/CVE-2022-29117 | 2022-05-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2083647 | 2022-05-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | .net Search vendor "Microsoft" for product ".net" | 5.0 Search vendor "Microsoft" for product ".net" and version "5.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Search vendor "Microsoft" for product ".net" | 6.0.0 Search vendor "Microsoft" for product ".net" and version "6.0.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Core Search vendor "Microsoft" for product ".net Core" | 3.1 Search vendor "Microsoft" for product ".net Core" and version "3.1" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio 2019 Search vendor "Microsoft" for product "Visual Studio 2019" | >= 16.0 <= 16.0.11 Search vendor "Microsoft" for product "Visual Studio 2019" and version " >= 16.0 <= 16.0.11" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio 2022 Search vendor "Microsoft" for product "Visual Studio 2022" | 17.0 Search vendor "Microsoft" for product "Visual Studio 2022" and version "17.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio 2022 Search vendor "Microsoft" for product "Visual Studio 2022" | 17.1 Search vendor "Microsoft" for product "Visual Studio 2022" and version "17.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 36 Search vendor "Fedoraproject" for product "Fedora" and version "36" | - |
Affected
|