CVE-2023-33141 is a Denial of Service vulnerability affecting Microsoft's Yet Another Reverse Proxy (YARP). With a CVSS score of 7.5 (HIGH), this vulnerability can be exploited remotely with low attack complexity, leading to a complete denial of service without requiring user interaction or privileges. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and community discussion and media coverage are minimal, indicating low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.1.2CPE matchmatch criteria | cpe:2.3:a:microsoft:yet_another_reverse_proxy:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:yet_another_reverse_proxy:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.