Impact
Allocation of resources without limits or throttling in the .NET runtime can be an attacker who can send requests over a network, leading to denial of service. The vulnerability falls under resource exhaustion (CWE-770) and allows the attacker to exhaust memory or other system resources, potentially halting the target application or host. The impact is loss of availability for the affected service.
Affected Systems
The affected products include Microsoft .NET 10.0, .NET 9.0, .NET 8.0, the .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1; and the Visual Studio IDEs Microsoft Visual Studio 2022 versions 17.12 and 17.14 and Microsoft Visual Studio 2026 version 18.7.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of approximately 1.03% indicates a low but non‑negligible exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation is documented. The attack vector is inferred to be remote over a network, requiring an attacker to send specially crafted input that causes the .NET runtime to allocate unbounded resources, thereby exhausting memory or CPU and rendering the service unavailable.
OpenCVE Enrichment
Github GHSA
Ubuntu USN