CVE-2022-21986: .NET Denial of Service Vulnerability
Published Feb 8, 2022
·Updated
.NET Denial of Service Vulnerability
Affected Software
13 affected componentsFixes available
Microsoft .NET 6.0
Microsoft Visual Studio 2019 (includes 16.0 - 16.8)=16.9
Microsoft Visual Studio 2019 (includes 16.0 - 16.10)=16.11
Microsoft Visual Studio 2019 for Mac=8.10
Microsoft .NET 5.0
Microsoft Visual Studio 2022=17.0
Microsoft .NET>=5.0<5.0.14
Microsoft .NET>=6.0.0<6.0.2
Microsoft Visual Studio 2019 Macos>=8.10<8.10.18
Microsoft Visual Studio 2019>=16.0<=16.11
Microsoft Visual Studio 2022>=17.0<17.0.6
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Event History
Feb 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Feb 9, 2022
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-21986?
CVE-2022-21986 is a .NET Denial of Service vulnerability that affects multiple Microsoft products including Visual Studio 2019 and .NET 5.0 and 6.0.
2
How severe is CVE-2022-21986?
CVE-2022-21986 has a severity rating of 7.5, which is considered high.
3
How do I fix the CVE-2022-21986 vulnerability in Visual Studio 2019?
To fix the CVE-2022-21986 vulnerability in Visual Studio 2019, you should update to version 16.9 or install the provided patch.
4
How do I fix the CVE-2022-21986 vulnerability in .NET 5.0?
To fix the CVE-2022-21986 vulnerability in .NET 5.0, you should update to the latest version or install the provided patch.
5
How do I fix the CVE-2022-21986 vulnerability in .NET 6.0?
To fix the CVE-2022-21986 vulnerability in .NET 6.0, you should update to the latest version or install the provided patch.