← Back to CVE List
Vulnerability Intelligence Report
.NET and Visual Studio Denial of Service Vulnerability

CVE-2023-38180

.NET and Visual Studio Denial of Service Vulnerability

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:14.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-400 ↗CWE-400 Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
Microsoft .NET 6.0 6.0.0 < 6.0.21 (affected)
Microsoft .NET 7.0 7.0.0 < 7.0.10 (affected)
Microsoft ASP.NET Core 2.1 2.0 < 2.1.40 (affected)
Microsoft Microsoft Visual Studio 2022 version 17.2 17.2.0 < 17.2.18 (affected)
Microsoft Microsoft Visual Studio 2022 version 17.4 17.4.0 < 17.4.10 (affected)
Microsoft Microsoft Visual Studio 2022 version 17.6 17.6.0 < 17.6.6 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
14.810%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2023-07-12T23:41:45
Published2023-08-08T18:52:31
Patch Date2023-08-08
Last Updated2026-08-10T15:12:01

LINK COPIED TO CLIPBOARD