QID 91898

Date Published: 2022-05-11

QID 91898: Microsoft .NET Security Update for May 2022

Microsoft has released a security Update for .NET which resolves Denial of Service Vulnerability.
This security update is rated Important for supported versions of .NET

Affected versions:
.NET 5.0 before version 5.0.17
.NET 6.0 before version 6.0.5
and .NET Core 3.1 before version 3.1.25

QID Detection Logic: Authenticated

This QID detects vulnerable versions of Microsoft .NET Core by checking the file version on windows.

Successful exploitation of this vulnerability could lead to Denial of Service Vulnerability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to CVE-2022-23267, CVE-2022-29117, and CVE-2022-29145 for more information pertaining to these vulnerabilities.

    CVEs related to QID 91898

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-23267 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23267
    CVE-2022-29117 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29117
    CVE-2022-29145 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29145