CVE-2019-1301 is a denial-of-service vulnerability in Microsoft .NET Core and PowerShell Core, stemming from improper handling of web requests. This high-severity vulnerability (CVSS 7.5) can be exploited remotely without user interaction, leading to a denial of service. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:2.1:*:*:*:*:*:*:* | ||
2.2CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:2.2:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell_core:6.1:*:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell_core:6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
High severity vulnerability that affects System.Management.Automation
Sep 13, 2019.NET Core Denial of Service Vulnerability
Sep 10, 2019dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service
Sep 10, 2019