CVE-2023-38180: Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-08-09. EPSS: 14% chance of exploitation in the next 30 days.
.NET and Visual Studio Denial of Service Vulnerability
Affected products
- Fedoraproject Fedora: version 37 only; version 38 only
- Microsoft .net: from 6.0.0, before 6.0.21 (fixed in 6.0.21); from 7.0.0, before 7.0.10 (fixed in 7.0.10)
- Microsoft ASP.NET Core: from 2.1, before 2.1.40 (fixed in 2.1.40)
- Microsoft Visual Studio 2022: from 17.2.0, before 17.2.18 (fixed in 17.2.18); from 17.4.0, before 17.4.10 (fixed in 17.4.10); from 17.6.0, before 17.6.6 (fixed in 17.6.6)
Published 2023-08-08. Last modified 2026-08-10.