CVE-2019-0820: High severity microsoft .net core runtime vulnerability
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Other sources
It was discovered that RegEx strings were not properly processed, which can be exploited by anauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0820
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0820?
CVE-2019-0820 is a denial of service vulnerability that exists in .NET Framework and .NET Core when processing RegEx strings.
How does CVE-2019-0820 affect Microsoft .NET Core?
CVE-2019-0820 affects Microsoft .NET Core versions 1.0, 1.1, 2.1, and 2.2.
How does CVE-2019-0820 affect Microsoft .NET Framework?
CVE-2019-0820 affects Microsoft .NET Framework versions 2.0 SP2, 3.0 SP2, and 3.5.
What is the severity of CVE-2019-0820?
CVE-2019-0820 has a severity rating of 7.5, indicating a high severity.
How do I fix CVE-2019-0820?
To fix CVE-2019-0820, it is recommended to apply the latest security updates provided by Microsoft or Red Hat.