First published: Tue Feb 06 2024(Updated: )
.NET Denial of Service Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ASP.NET Core | =6.0 | |
Microsoft ASP.NET Core | =7.0 | |
Microsoft ASP.NET Core | =8.0 | |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | <=6.0.26 | 6.0.27 |
ubuntu/dotnet6 | <6.0.127-0ubuntu1~22.04.1 | 6.0.127-0ubuntu1~22.04.1 |
ubuntu/dotnet6 | <6.0.127-0ubuntu1~23.10.1 | 6.0.127-0ubuntu1~23.10.1 |
ubuntu/dotnet6 | <6.0.27 | 6.0.27 |
ubuntu/dotnet7 | <7.0.116-0ubuntu1~22.04.1 | 7.0.116-0ubuntu1~22.04.1 |
ubuntu/dotnet7 | <7.0.116-0ubuntu1~23.10.1 | 7.0.116-0ubuntu1~23.10.1 |
ubuntu/dotnet7 | <7.0.16 | 7.0.16 |
ubuntu/dotnet8 | <8.0.102-8.0.2-0ubuntu1~22.04.1 | 8.0.102-8.0.2-0ubuntu1~22.04.1 |
ubuntu/dotnet8 | <8.0.102-8.0.2-0ubuntu1~23.10.1 | 8.0.102-8.0.2-0ubuntu1~23.10.1 |
ubuntu/dotnet8 | <8.0.2 | 8.0.2 |
Microsoft Visual Studio | =17.6 | |
Microsoft Visual Studio | =17.8 | |
Microsoft ASP.NET Core | >=6.0.0<6.0.27 | |
Microsoft ASP.NET Core | >=7.0.0<7.0.16 | |
Microsoft ASP.NET Core | >=8.0.0<8.0.2 | |
Microsoft Visual Studio | >=17.4.0<17.4.16 | |
Microsoft Visual Studio | >=17.6.0<17.6.12 | |
Microsoft Visual Studio | >=17.8.0<17.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21386 has been classified as a Denial of Service vulnerability.
To fix CVE-2024-21386, update to the patched versions of ASP.NET Core or Visual Studio as specified in the advisory.
CVE-2024-21386 affects ASP.NET Core versions 6.0, 7.0, and 8.0, as well as specific versions of Visual Studio 2022.
It is advisable to assume there may be exploit possibilities, hence immediate patching is recommended.
CVE-2024-21386 impacts multiple platforms including Windows, Linux, and macOS environments using affected versions.