ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds Microsoft .NET Vulnerability to KEV Catalog Due to Active Exploitation

highExploit / PoC exploited in the wildimportance 60CVE-2023-38180

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-38180
Unauthenticated DoS in Microsoft .NET, ASP.NET Core and Visual Studio 2022

CVE-2023-38180 is a denial-of-service vulnerability in Microsoft .NET and Visual Studio 2022 caused by uncontrolled resource consumption (CWE-400). Per the CVSS vector, a remote, unauthenticated attacker can trigger it over the network with no privileges or user interaction required, causing affected applications or services to exhaust resources and become unavailable. The attacker gains only availability impact (high availability severity, no confidentiality or integrity impact), but this can take down ASP.NET Core web applications and other .NET-based services. Any organization running vulnerable .NET runtimes, ASP.NET Core applications, or Visual Studio 2022 is exposed, and Fedora also ships affected .NET packages. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-08-09, it was among the two actively exploited flaws fixed in Microsoft's August 2023 Patch Tuesday, and EPSS assigns a 14.0% 30-day exploitation probability (96th percentile).

Do: Apply the August 2023 Microsoft security updates for all affected .NET, ASP.NET Core, and Visual Studio 2022 versions listed in Microsoft's advisory, and install the updated .NET packages on Fedora; because this flaw is in CISA's KEV catalog, the required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. After updating, rebuild or restart .NET applications so they run on the patched runtime, and monitor internet-facing .NET services for signs of resource-exhaustion denial-of-service. No public proof-of-concept is known, but active exploitation has been reported, so patching should be treated as urgent.

7.514% KEV
  • microsoft .NET / .NET Core (including ASP.NET Core workloads)
  • microsoft ASP.NET Core
  • microsoft Visual Studio 2022
  • +1 more
masshundreds of millions of potential installations (ubiquity of the .NET runtime and ASP.NET Core in server and web deployments)

Indicators of compromiseAll →

TypeIndicatorContext
domainasp.netkilled attacker." Affected versions of the software include ASP.NET Core 2.1, .NET 6.0, .NET 7.0, Microsoft Visual Studio 2022
Full article250 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 11, 2023Endpoint Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched security flaw in Microsoft's .NET and Visual Studio products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Tracked as CVE-2023-38180 (CVSS score: 7.5), the high-severity flaw relates to a case denial-of-service (DoS) impacting .NET and Visual Studio.

It was addressed by Microsoft as part of its August 2023 Patch Tuesday updates shipped earlier this week, tagging it with an "Exploitation More Likely" assessment.

While exact details surrounding the nature of exploitation are unclear, the Windows maker has acknowledged the existence of a proof-of-concept (PoC) in its advisory. It also said that attacks leveraging the flaw can be pulled off without any additional privileges or user interaction.

"Proof-of-concept exploit code is available, or an attack demonstration is not practical for most systems," the company said. "The code or technique is not functional in all situations and may require substantial modification by a skilled attacker."

Affected versions of the software include ASP.NET Core 2.1, .NET 6.0, .NET 7.0, Microsoft Visual Studio 2022 version 17.2, Microsoft Visual Studio 2022 version 17.4, and Microsoft Visual Studio 2022 version 17.6.

To mitigate potential risks, CISA has recommended Federal Civilian Executive Branch (FCEB) agencies to apply vendor-provided fixes for the vulnerability by August 30, 2023.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/08/cisa-adds-microsoft-net-vulnerability.html