Impact
A type‑confusion flaw in .NET Core permits an attacker to trigger a denial‑of‑service condition by sending specially crafted data over the network. The incompatible type, resulting in an exception that may to legitimate users.
Affected Systems
The flaw affects Microsoft .NET 10.0, .NET 9.0, and .NET 8.0. Any installation of these runtimes that processes untrusted network data is potentially vulnerable; the exact patch level is not specified in the input, but the advisory references a security update for all listed versions.
Risk and Exploitability
With a CVSS score of 7.5 and an EPSS probability of 0.01105 (~1.11 %), the risk of exploitation is moderate but present. The vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation yet. Based on the description it is inferred that an unauthorized attacker can exploit the sending exploitation would cause application crashes or hangs, leading to service interruption for affected users.
OpenCVE Enrichment
Github GHSA
Ubuntu USN