CVE-2019-0820
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Affected (27)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp2 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | Version r2 sp1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.5.2 |
Configuration F
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration G
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6.1 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.7.1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1607 |
Microsoft Windows 7 | All versions |
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Server 2012 | All versions |
Microsoft Windows Server 2016 | All versions |
Microsoft Windows Server 2019 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.1 | |
| Version 8.2 | |
| Version 8.2 |
References (4)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.