7.5

CVE-2024-43484

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Data is provided by the National Vulnerability Database (NVD)
Microsoft.Net Framework Version3.5 Update-
   MicrosoftWindows 10 21h2 Version-
   MicrosoftWindows 10 22h2 Version-
   MicrosoftWindows 11 22h2 Version-
   MicrosoftWindows 11 23h2 Version-
   MicrosoftWindows 11 24h2 Version-
   MicrosoftWindows Server 2022
   MicrosoftWindows Server 2022 23h2
Microsoft.Net Framework Version4.8.1
   MicrosoftWindows 10 21h2 Version-
   MicrosoftWindows 10 22h2 Version-
   MicrosoftWindows 11 22h2 Version-
   MicrosoftWindows 11 23h2 Version-
   MicrosoftWindows 11 24h2 Version-
   MicrosoftWindows Server 2022
   MicrosoftWindows Server 2022 23h2
Microsoft.Net Framework Version3.5 Update-
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx86
   MicrosoftWindows Server 2012 HwPlatformx64
   MicrosoftWindows Server 2012 Versionr2 HwPlatformx64
Microsoft.Net Framework Version4.8
   MicrosoftWindows 10 1607 HwPlatformx64
   MicrosoftWindows 10 1607 HwPlatformx86
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
   MicrosoftWindows Server 2016
Microsoft.Net Framework Version3.5 Update-
   MicrosoftWindows 10 1607 HwPlatformx64
   MicrosoftWindows 10 1607 HwPlatformx86
   MicrosoftWindows 10 1809
   MicrosoftWindows Server 2016
   MicrosoftWindows Server 2019
Microsoft.Net Framework Version4.7.2
   MicrosoftWindows 10 1607 HwPlatformx64
   MicrosoftWindows 10 1607 HwPlatformx86
   MicrosoftWindows 10 1809
   MicrosoftWindows Server 2016
   MicrosoftWindows Server 2019
Microsoft.Net Framework Version3.5.1
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
Microsoft.Net Framework Version4.6.2
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx86
Microsoft.Net Framework Version4.6.2
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.7
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.7.1
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.7.2
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.6
   MicrosoftWindows 10 1507 Version-
Microsoft.Net Framework Version4.6.2
   MicrosoftWindows 10 1507 Version-
Microsoft.Net Framework Version3.0 Updatesp2
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx86
Microsoft.Net Framework Version2.0 Updatesp2
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx86
Microsoft.Net Version >= 6.0.0 < 6.0.35
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
Microsoft.Net Version >= 8.0.0 < 8.0.10
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
MicrosoftVisual Studio 2022 Version >= 17.6 < 17.6.20
MicrosoftVisual Studio 2022 Version >= 17.8 < 17.8.15
MicrosoftVisual Studio 2022 Version >= 17.10 < 17.10.8
MicrosoftVisual Studio 2022 Version >= 17.11 < 17.11.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.22% 0.84
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-407 Inefficient Algorithmic Complexity

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.