CVE-2023-38180

Vulnerability updated 22 days ago (2024-11-29T14:19:19.023Z)
Download STIX
Preview STIX
CVE-2023-38180 is a significant Denial of Service (DoS) vulnerability that affects Microsoft's .NET framework and Visual Studio. This flaw in the software design or implementation has been actively exploited in the wild, posing a severe threat to systems running these applications. The vulnerability can cause a denial of service against .NET applications and the Visual Studio Integrated Development Environment (IDE), disrupting their normal functioning. Reports have indicated that this vulnerability, along with multiple remote code execution vulnerabilities (CVE-2023-29328, CVE-2023-29330, CVE-2023-35385, CVE-2023-36895, CVE-2023-36910, and CVE-2023-36911), are at high risk of exploitation. This situation raises concerns about the potential for widespread system disruptions and unauthorized access to sensitive data. The Common Vulnerability Scoring System (CVSS) score for CVE-2023-38180 is 7.5, indicating its severity. Microsoft has acknowledged the existence of a Proof-of-Concept (PoC) exploit for the CVE-2023-38180 vulnerability. However, they noted that the PoC code or technique may not be functional in all situations and might require substantial modification by a skilled attacker. Microsoft has addressed this zero-day vulnerability and recommends immediate patching to mitigate the risk of exploitation and ensure the security of .NET applications and Visual Studio IDE.
Description last updated: 2024-05-04T17:13:48.611Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Microsoft
Exploit
Denial of Se...
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2023-38180 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CISA
6 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CrowdStrike
a year ago
CERT-EU
a year ago
Malwarebytes
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CISA
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
InfoSecurity-magazine
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Krebs on Security
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago