CVE-2024-43499 is a Denial of Service vulnerability affecting .NET and Visual Studio across Apple, Linux, and Microsoft platforms. With a CVSS score of 7.5 (High), it can be exploited remotely without user interaction, leading to a denial of service. While not currently on CISA's KEV catalog, there is no public exploit code available, and it has received limited community discussion and media coverage, though it was addressed in Microsoft's November 2024 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:9.0.0:*:*:*:*:*:*:* | ||
>= 17.6, < 17.6.21CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.8, < 17.8.16CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, <= 17.10.9CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.11.0, < 17.11.6CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.