CVE-2023-21538: .NET Denial of Service Vulnerability
Published Jan 10, 2023
·Updated
.NET Denial of Service Vulnerability
Affected Software
18 affected componentsFixes available
Microsoft .NET 6.0
nuget/Microsoft.NetCore.App.Runtime.win-x86>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.win-x64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.win-arm64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.win-arm>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.osx-x64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.osx-arm64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.linux-x64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.linux-musl-x64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.linux-arm64>=6.0.0<6.0.13
6.0.13
nuget/Microsoft.NetCore.App.Runtime.linux-arm>=6.0.0<6.0.13
6.0.13
Microsoft PowerShell 7.2
Microsoft .NET=6.0.0
Microsoft PowerShell=7.2
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·10:43 PM
Frequently Asked Questions
1
What is CVE-2023-21538?
CVE-2023-21538 is a .NET Denial of Service Vulnerability.
2
Which software versions are affected by CVE-2023-21538?
The affected software versions are Microsoft .NET 6.0, Microsoft PowerShell 7.2, and Fedoraproject Fedora 36 and 37.
3
How severe is CVE-2023-21538?
CVE-2023-21538 has a severity score of 7.5 (high).
4
How can I fix CVE-2023-21538 for Microsoft .NET 6.0?
To fix CVE-2023-21538 for Microsoft .NET 6.0, you can download the patch from the Microsoft website.
5
Where can I find more information about CVE-2023-21538?
You can find more information about CVE-2023-21538 on the Microsoft Security Response Center website.