CVE-2023-38171 is a Microsoft QUIC Denial of Service vulnerability affecting Microsoft .NET, Visual Studio 2022, Windows 11 22H2, and Windows Server 2022. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, leading to a complete denial of service. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness. It is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.12CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 17.2.0, < 17.2.20CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.4.0, < 17.4.12CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.6.0, < 17.6.8CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.7.0, < 17.7.5CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
Oct 10, 2023Microsoft QUIC Denial of Service Vulnerability
Oct 10, 2023dotnet: NULL pointer dereference in MsQuic.dll may lead to denial of service
Oct 10, 2023