.Net Framework and .Net Core Denial of Service Vulnerability
Released: May 14, 2019
Last updated: Mar 25, 2020
- Assigning CNA
- Microsoft
- CVE.org link
- CVE-2019-0980
Executive Summary
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework or .NET Core application.
The update addresses the vulnerability by correcting how .NET Framework or .NET Core web applications handles web requests.
Exploitability
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
- Publicly disclosed
- No
- Exploited
- No
- Exploitability assessment
- Exploitation Less Likely
Acknowledgements
- Nemanja Mijailovic Nemanja Mijailovic's Blog
Security Updates
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle.
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
Disclaimer
Revisions
The following revisions have been made in the Security Updates table: 1. Removed updates for .NET Framework installed on Windows 10 Version 1809 for ARM64-based Systems because .NET Framework is not supported on this architecture. 2. Corrected the Download to "Security Update" for all versions of Windows 10 version 1809. Customers who have successfully installed the updates for .NET Framework installed on Windows 10 version 1809 do not need to take any further action.
Revised the Security Updates table to include PowerShell Core 6.1 and 6.2 because they are affected by CVE-2019-0980. See https://github.com/PowerShell/Announcements/issues/16 for more information.
Information published.