.NET Framework Denial of Service Vulnerability
Released: May 14, 2019
Last updated: Mar 25, 2020
- Assigning CNA
- Microsoft
- CVE.org link
- CVE-2019-0864
Executive Summary
A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
The security update addresses the vulnerability by correcting how .NET Framework handle objects in heap memory.
Exploitability
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
- Publicly disclosed
- No
- Exploited
- No
- Exploitability assessment
- Exploitation Less Likely
FAQ
What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
Acknowledgements
- Keqi Hu and zhangjie from Chengdu Security Response Center of Qihoo 360 Technology Co. Ltd.
Security Updates
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle.
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
Disclaimer
Revisions
The following revisions have been made in the Security Updates table: 1. Removed updates for .NET Framework installed on Windows 10 Version 1809 for ARM64-based Systems because .NET Framework is not supported on this architecture. 2. Corrected the Download to "Security Update" for all versions of Windows 10 version 1809. Customers who have successfully installed the updates for .NET Framework installed on Windows 10 version 1809 do not need to take any further action.
Information published.