CVE-2021-24111: .NET Framework Denial of Service Vulnerability
Published Feb 25, 2021
·Updated
.NET Framework Denial of Service Vulnerability
Affected Software
70 affected components
All of the following
Microsoft .NET Framework=4.6
Microsoft Windows Server 2008=sp2
All of the following
Any of the following
Microsoft .NET Framework=4.6.2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Any of the following
Microsoft Windows 10=1607
Microsoft Windows Server 2016
All of the following
Any of the following
Microsoft .NET Framework=4.6
Microsoft .NET Framework=4.6.1
Microsoft .NET Framework=4.6.2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Any of the following
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
All of the following
Microsoft .NET Framework=4.7.2
Any of the following
Microsoft Windows 10=1803
Microsoft Windows Server 2019
All of the following
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=1607
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Microsoft .NET Framework=4.6
Microsoft Windows Server 2008=sp2
Microsoft .NET Framework=4.6.2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Microsoft Windows 10=1607
Microsoft Windows Server 2016
Microsoft .NET Framework=4.6.1
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows 10=1803
Microsoft Windows Server 2019
Microsoft .NET Framework=4.8
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Remediation
Event History
Feb 25, 2021
CVE Published
11:01 PM
Data Sourced
11:01 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-24111?
CVE-2021-24111 is a Denial of Service vulnerability in the .NET Framework.
2
How severe is CVE-2021-24111?
CVE-2021-24111 has a severity rating of 7.5, which is considered high.
3
Which versions of the .NET Framework are affected by CVE-2021-24111?
Versions 4.6, 4.6.2, 4.7, 4.7.1, 4.7.2, and 4.8 of the .NET Framework are affected by CVE-2021-24111.
4
How can I fix CVE-2021-24111?
To fix CVE-2021-24111, update to a version of the .NET Framework that is not affected by the vulnerability.
5
Where can I find more information about CVE-2021-24111?
You can find more information about CVE-2021-24111 on the Microsoft Security Guidance Advisory page: [link](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-24111).