CVE-2023-29331: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Overview
- Severity
- High (CVSS 7.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
- Category
- Denial of Service
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2023-Jun
- Released
- 2023-06-13
- Last Updated
- 2023-06-29
- EPSS Score
- 1.13% (percentile: 78.3%)
Affected Products (75)
Developer Tools
- .NET 6.0
- .NET 7.0
- Microsoft Visual Studio 2022 version 17.0
- Microsoft Visual Studio 2022 version 17.2
- Microsoft Visual Studio 2022 version 17.4
- Microsoft Visual Studio 2022 version 17.6
- PowerShell 7.2
- PowerShell 7.3
- Microsoft .NET Framework 4.8 on Windows Server 2012
- Microsoft .NET Framework 4.8 on Windows Server 2016
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
- Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems
- Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)
- Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems
- Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Microsoft .NET Framework 4.8 on Windows Server 2012 R2
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)
- Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 21H2 for ARM64-based Systems
- ... and 25 more
Security Updates (39)
Acknowledgments
Kevin Jones, GitHub
Revision History
- 2023-06-13: Information published.
- 2023-06-29: Revised the Security Updates table to include PowerShell 7.2 and PowerShell 7.3 because these versions of PowerShell 7 are affected by this vulnerability. See https://github.com/PowerShell/Announcements/issues/44 for more information.