7.5

CVE-2024-43499

.NET and Visual Studio Denial of Service Vulnerability

Data is provided by the National Vulnerability Database (NVD)
Microsoft.Net Version9.0.0
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
MicrosoftVisual Studio 2022 Version >= 17.6 < 17.6.21
MicrosoftVisual Studio 2022 Version >= 17.8 < 17.8.16
MicrosoftVisual Studio 2022 Version >= 17.10.0 <= 17.10.9
MicrosoftVisual Studio 2022 Version >= 17.11.0 < 17.11.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.44% 0.801
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

CWE-606 Unchecked Input for Loop Condition

The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.