← לוח פגיעויות

CVE-2020-1108

גבוהה 7.5

תיאור (מקור, אנגלית)

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
6% (אחוזון 100) נכון ל-16/9/2026

מוצרים מושפעים

microsoft: .net; microsoft: .net core; microsoft: .net framework; microsoft: windows server 2008; microsoft: windows 8.1; microsoft: windows server 2012; microsoft: windows 10; microsoft: windows server 2016; microsoft: windows server 2019; microsoft: windows 7; microsoft: windows rt 8.1; microsoft: visual studio 2017; microsoft: visual studio 2019; microsoft: powershell; microsoft: powershell core

קישורים