QID 91889

Date Published: 2022-04-13

QID 91889: Microsoft .NET Framework Denial of Service (DoS) Vulnerability for April 2022

A denial of service vulnerability exist in Microsoft .Net Framework.

Following KBs are covered in this detection:
KB5012117
KB5012118
KB5012120
KB5012121
KB5012123
KB5012324
KB5012325
KB5012326
KB5012327
KB5012328
KB5012329
KB5012330
KB5012331
KB5012332
This security update is rated Important for supported versions of Microsoft .NET Framework.

.NET Framework 3.5, 3.5.1, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 and 4.8

QID Detection Logic (Authenticated):
- Checks for vulnerable version of System.web.dll for .Net Framework

Successful exploitation allows attacker to cause denial of service vulnerability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to CVE-2022-26832 for more details pertaining to this vulnerability.

    CVEs related to QID 91889

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-26832 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26832