CVE-2014-4072

Description

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka .NET Framework Denial of Service Vulnerability.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
39.634

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack 2 (KB2972207)Windows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 (KB2972214) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 (KB2972214) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB2973115) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB2973115) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2972215) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2972215) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2974268) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2974268) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2974269) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2974269) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2972216) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2972216) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2972211) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2972211) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2973112) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2973112) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2972212) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2972212) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2973113) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2973113) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2977766) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2977766) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2972213) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2972213) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2973114) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2973114) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 and .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2977765) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 and .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2977765) x64 bases systemsWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-16133Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack 2 (KB2972207)
PATCH-16134Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 (KB2972214)
PATCH-16135Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 (KB2972214)
PATCH-16136Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB2973115)
PATCH-16137Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB2973115)
PATCH-16138Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2972215)
PATCH-16139Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2972215)
PATCH-16140Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2974268)
PATCH-16141Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2974268)
PATCH-16144Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2972216)
PATCH-16145Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2972216)
PATCH-16146Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2972211)
PATCH-16147Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2972211)
PATCH-16148Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2973112)
PATCH-16149Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2973112)
PATCH-16150Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2972212)
PATCH-16152Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2973113)
PATCH-16153Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2973113)
PATCH-16154Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2977766)
PATCH-16155Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2977766)
PATCH-16156Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2972213)
PATCH-16157Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2972213)
PATCH-16158Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2973114)
PATCH-16159Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2973114)
PATCH-16160Security Update for Microsoft .NET Framework 4.5.1 and .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1 (KB2977765)
PATCH-16161Security Update for Microsoft .NET Framework 4.5.1 and .NET Framework 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2977765)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234