CVE-2023-38171: Microsoft .net

High severity, CVSS 7.5. EPSS: 69.7% chance of exploitation in the next 30 days.

Microsoft QUIC Denial of Service Vulnerability

Affected products

  • Microsoft .net: from 7.0.0, before 7.0.12 (fixed in 7.0.12)
  • Microsoft Visual Studio 2022: from 17.2.0, before 17.2.20 (fixed in 17.2.20); from 17.4.0, before 17.4.12 (fixed in 17.4.12); from 17.6.0, before 17.6.8 (fixed in 17.6.8); from 17.7.0, before 17.7.5 (fixed in 17.7.5)
  • Microsoft Windows 11 22h2: before 10.0.22621.2428 (fixed in 10.0.22621.2428)
  • Microsoft Windows Server 2022: affected versions not specified

Published 2023-10-10. Last modified 2026-06-17.