HIGH · 7.5

CVE-2020-1108

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service aga...

Vulnerability Description

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Microsoft.Net5.0
Microsoft.Net Core>= 2.1, <= 2.1.18
Microsoft.Net Framework2.0
MicrosoftWindows Server 2008-
MicrosoftWindows 8.1-
MicrosoftWindows Server 2012-
MicrosoftWindows 101607
MicrosoftWindows Server 2016All versions
MicrosoftWindows Server 2019-
MicrosoftWindows 7-
MicrosoftWindows Rt 8.1-
MicrosoftVisual Studio 201715.9
MicrosoftVisual Studio 201916.0
MicrosoftPowershell7.0
MicrosoftPowershell Core6.2

References

FAQ

What is CVE-2020-1108?

CVE-2020-1108 is a vulnerability with a CVSS score of 7.5 (HIGH). A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service aga...

How severe is CVE-2020-1108?

CVE-2020-1108 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-1108?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft .Net, Microsoft .Net Core, Microsoft .Net Framework, Microsoft Windows Server 2008, Microsoft Windows 8.1.