CVE-2014-0253: Input Validation
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resource consumption for a (1) stale or (2) closed connection, as exploited in the wild in February 2014, aka "POST Request DoS Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0253?
CVE-2014-0253 is classified as a denial of service vulnerability, which can impact service availability.
How do I fix CVE-2014-0253?
To fix CVE-2014-0253, it is recommended to upgrade to a supported version of the Microsoft .NET Framework that addresses this vulnerability.
What versions of Microsoft .NET Framework are affected by CVE-2014-0253?
CVE-2014-0253 affects Microsoft .NET Framework versions 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1.
What type of attack does CVE-2014-0253 enable?
CVE-2014-0253 enables remote attackers to launch a denial of service attack, causing the ASP.NET daemon to hang.
Is CVE-2014-0253 exploit publicly available?
Details about how to exploit CVE-2014-0253 may be publicly discussed, but no specific exploits have been documented.