CVE-2024-21319: Microsoft .net

Medium severity, CVSS 6.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Microsoft Identity Denial of service vulnerability

Affected products

  • Microsoft .net: from 6.0.0, before 6.0.26 (fixed in 6.0.26); from 7.0.0, before 7.0.15 (fixed in 7.0.15); from 8.0.0, before 8.0.1 (fixed in 8.0.1)
  • Microsoft Identity Model: from 5.0.0, before 5.7.0 (fixed in 5.7.0); from 6.0.0, before 6.34.0 (fixed in 6.34.0); from 7.0.0, before 7.1.2 (fixed in 7.1.2)
  • Microsoft Visual Studio 2022: from 17.2.0, before 17.2.23 (fixed in 17.2.23); from 17.4.0, before 17.4.15 (fixed in 17.4.15); from 17.6.0, before 17.6.11 (fixed in 17.6.11); from 17.8.0, before 17.8.4 (fixed in 17.8.4)

Published 2024-01-09. Last modified 2026-06-17.