Impact
This vulnerability arises from the allocation of resources without limits or throttling in .NET Framework, identified as CWE‑770 (Resource Exhaustion). The flaw enables an unauthorized attacker to force the system to consume excessive memory or CPU, thereby disrupting legitimate services over a network. The impact is strictly a denial of service, affecting availability but not confidentiality or integrity.
Affected Systems
Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1, and the newer .NET 8.0, 9.0, and 10.0 releases are all affected. Additionally, Visual Studio 2022 versions 17.12, 17.14, and Visual Studio 2026 18.7 are impacted, as well as the Red Hat Hummingbird 1 component. Any system running these Microsoft or Red Hat products on an untrusted or public network is at risk.
Risk and Exploitability
The description indicates that an unauthorized attacker can deny service over a network. The CVSS score of 7.5 signals a moderate‑to‑high risk level, and the EPSS score of less than 1% suggests that widespread exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalog. While no direct privilege escalation is disclosed, the resulting denial of service may disrupt business operations and potentially provide a stepping‑stone for further attacks.
OpenCVE Enrichment
Github GHSA
Ubuntu USN