CVE-2023-38171: Microsoft QUIC Denial of Service Vulnerability
Impact The MsQuic server application or process will crash, resulting in a denial of service.
Patches The following patch was made:
- Don't Allow Version Negotiation Packets for Server Connections - https://github.com/microsoft/msquic/commit/3226cff07d22662f16fc98d605656860e64cd343
Workarounds Beyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality.
Other sources
Microsoft QUIC Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-38171?
CVE-2023-38171 is a Microsoft QUIC Denial of Service vulnerability that can cause the MsQuic server to crash, resulting in a denial of service.
How severe is CVE-2023-38171?
CVE-2023-38171 has a severity rating of 7.5, which is considered high.
Which software products are affected by CVE-2023-38171?
Software products affected by CVE-2023-38171 include Microsoft .NET 7.0, Visual Studio 2022 (versions 17.6 and 17.7), Windows Server 2022 (Server Core Installation), Visual Studio 2022 (version 17.2), and Windows 11 (versions 22H2 and 21H2).
How can I patch CVE-2023-38171?
You can apply the necessary patches for CVE-2023-38171 by following the provided URLs for each affected software product: Microsoft .NET 7.0 (https://dotnet.microsoft.com/download/dotnet/7.0), Visual Studio 2022 (version 17.6 - https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6, version 17.7 - https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.7), and Windows Server 2022 (https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5031364 for Server Core Installation).
What is the Common Weakness Enumeration (CWE) for CVE-2023-38171?
The Common Weakness Enumeration (CWE) for CVE-2023-38171 is CWE-400.