CVE-2024-43483
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. The System.Security.Cryptography.Cose, System.IO.Packaging and System.Runtime.Caching components may be exposed to hostile input, making them susceptible to hash flooding attacks, resulting in denial of service.
Brennan Conroy discovered that the .NET Kestrel web server did not properly handle closing HTTP/3 streams under certain circumstances. An attacker could possibly use this issue to achieve remote code execution. This vulnerability only impacted Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. It was discovered that .NET components designed to process malicious input were susceptible to hash flooding attacks. An attacker could possibly use this issue to cause a denial of service, resulting in a crash.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-08-14 CVE Reserved
- 2024-10-08 CVE Published
- 2025-01-29 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-407: Inefficient Algorithmic Complexity
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43483 | 2024-10-08 | |
https://access.redhat.com/security/cve/CVE-2024-43483 | 2024-10-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2315730 | 2024-10-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | PowerShell 7.2 Search vendor "Microsoft" for product "PowerShell 7.2" | >= 7.2.0 < 7.2.24 Search vendor "Microsoft" for product "PowerShell 7.2" and version " >= 7.2.0 < 7.2.24" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | PowerShell 7.4 Search vendor "Microsoft" for product "PowerShell 7.4" | >= 7.4.0 < 7.4.6 Search vendor "Microsoft" for product "PowerShell 7.4" and version " >= 7.4.0 < 7.4.6" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft Visual Studio 2022 Version 17.6 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.6" | >= 17.6.0 < 17.6.20 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.6" and version " >= 17.6.0 < 17.6.20" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft Visual Studio 2022 Version 17.8 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.8" | >= 17.8.0 < 17.8.15 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.8" and version " >= 17.8.0 < 17.8.15" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft Visual Studio 2022 Version 17.10 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.10" | >= 17.10.0 < 17.10.8 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.10" and version " >= 17.10.0 < 17.10.8" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft Visual Studio 2022 Version 17.11 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.11" | >= 17.11.0 < 17.11.5 Search vendor "Microsoft" for product "Microsoft Visual Studio 2022 Version 17.11" and version " >= 17.11.0 < 17.11.5" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .NET 8.0 Search vendor "Microsoft" for product ".NET 8.0" | >= 8.0.0 < 8.0.10 Search vendor "Microsoft" for product ".NET 8.0" and version " >= 8.0.0 < 8.0.10" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .NET 6.0 Search vendor "Microsoft" for product ".NET 6.0" | >= 6.0.0 < 6.0.35 Search vendor "Microsoft" for product ".NET 6.0" and version " >= 6.0.0 < 6.0.35" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 4.8 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.8" | >= 4.8.0.0 < 4.8.04762.01 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.8" and version " >= 4.8.0.0 < 4.8.04762.01" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 3.5 AND 4.8 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5 AND 4.8" | >= 4.8.0.0 < 4.8.04762.01 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5 AND 4.8" and version " >= 4.8.0.0 < 4.8.04762.01" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 3.5 AND 4.7.2 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5 AND 4.7.2" | >= 4.7.0.0 < 4.7.04115.01 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5 AND 4.7.2" and version " >= 4.7.0.0 < 4.7.04115.01" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2" | >= 4.7.0.0 < 4.7.04115.01 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2" and version " >= 4.7.0.0 < 4.7.04115.01" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 3.5 AND 4.8.1 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5 AND 4.8.1" | >= 4.8.1.0.0 < 4.8.1.9277.03 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5 AND 4.8.1" and version " >= 4.8.1.0.0 < 4.8.1.9277.03" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 4.6.2 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.6.2" | >= 4.7.0.0 < 4.7.04115.01 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.6.2" and version " >= 4.7.0.0 < 4.7.04115.01" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 4.6/4.6.2 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.6/4.6.2" | >= 10.0.0.0 < 10.0.10240.20796 Search vendor "Microsoft" for product "Microsoft .NET Framework 4.6/4.6.2" and version " >= 10.0.0.0 < 10.0.10240.20796" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 2.0 Service Pack 2 Search vendor "Microsoft" for product "Microsoft .NET Framework 2.0 Service Pack 2" | >= 2.0.0.0 < 3.0.30729.8974 Search vendor "Microsoft" for product "Microsoft .NET Framework 2.0 Service Pack 2" and version " >= 2.0.0.0 < 3.0.30729.8974" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 3.0 Service Pack 2 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.0 Service Pack 2" | >= 3.0.0.0 < 3.0.30729.8974 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.0 Service Pack 2" and version " >= 3.0.0.0 < 3.0.30729.8974" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 3.5 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5" | >= 3.5.0.0 < 3.5.30729.8973 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5" and version " >= 3.5.0.0 < 3.5.30729.8973" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Microsoft .NET Framework 3.5.1 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5.1" | >= 3.5.0.0.0 < 3.5.1.30729.8974 Search vendor "Microsoft" for product "Microsoft .NET Framework 3.5.1" and version " >= 3.5.0.0.0 < 3.5.1.30729.8974" | en |
Affected
|