Microsoft .NET
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*
- >= 9.0, < 9.0.14
- >= 10.0, < 10.0.4
A denial-of-service vulnerability has been identified in .NET versions 10.0.4 and 9.0.14, as well as in Microsoft.Bcl.Memory versions 10.0.4 and 9.0.14. This vulnerability arises from an out-of-bounds read, which allows an unauthorized attacker to disrupt service over a network.
Exploitation of this vulnerability leads to a denial-of-service condition, causing applications to become unresponsive or unavailable.
Users can download the security update for .NET 9.0 or 10.0 from the official .NET website. For Microsoft.Bcl.Memory, the security update is available on NuGet. After downloading the update, it should be installed according to the standard procedure for applying updates in the respective environment.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.