First published: Wed Nov 15 2017(Updated: )
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ASP.NET Core | =1.0 | |
Microsoft ASP.NET Core | =1.1 | |
Microsoft ASP.NET Core | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11883 is classified as a denial of service vulnerability.
To fix CVE-2017-11883, it is recommended to update to a patched version of .NET Core.
CVE-2017-11883 affects ASP.NET Core versions 1.0, 1.1, and 2.0.
Yes, CVE-2017-11883 allows unauthenticated attackers to remotely exploit the vulnerability.
CVE-2017-11883 facilitates denial of service attacks against affected web applications.