Beveiligingsadvies

CVE-2014-0253

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2014-02-12 02:00:00
Laatst bijgewerkt 2024-08-06 09:13:09
Toegewezen door microsoft
CVSS-score geen score
Status PUBLISHED

Beschrijving

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resource consumption for a (1) stale or (2) closed connection, as exploited in the wild in February 2014, aka "POST Request DoS Vulnerability."