CVE-2024-43484
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: secure@microsoft.com (Secondary)
Description
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Affected (17)
Products: Microsoft: .net Framework, .net, Visual Studio 2022
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 21h2 | All versions |
Microsoft Windows 10 22h2 | All versions |
Microsoft Windows 11 22h2 | All versions |
Microsoft Windows 11 23h2 | All versions |
Microsoft Windows 11 24h2 | All versions |
Microsoft Windows Server 2022 23h2 | All versions |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 21h2 | All versions |
Microsoft Windows 10 22h2 | All versions |
Microsoft Windows 11 21h2 | All versions |
Microsoft Windows Server 2022 | All versions |
Configuration C
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2012 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 1607 | All versions |
Microsoft Windows 10 1809 | All versions |
Microsoft Windows Server 2016 | All versions |
Microsoft Windows Server 2019 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.7.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Server 2012 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6.2 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 1507 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 sp2 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp2 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration L
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 17.10 to 17.10.8 |
Related CWEs
CWE-407
Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
CWE-789
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
References (2)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.