CVE-2024-26190: Microsoft .net

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

Microsoft QUIC Denial of Service Vulnerability

Affected products

  • Microsoft .net: from 7.0.0, before 7.0.17 (fixed in 7.0.17); from 8.0.0, before 8.0.3 (fixed in 8.0.3)
  • Microsoft PowerShell: from 7.3, before 7.3.12 (fixed in 7.3.12); from 7.4, before 7.4.2 (fixed in 7.4.2)
  • Microsoft Visual Studio 2022: from 17.4.0, before 17.4.17 (fixed in 17.4.17); from 17.6.0, before 17.6.13 (fixed in 17.6.13); from 17.8.0, before 17.8.8 (fixed in 17.8.8); from 17.9.0, before 17.9.3 (fixed in 17.9.3)
  • Microsoft Windows 11 21h2: before 10.0.22000.2836 (fixed in 10.0.22000.2836)
  • Microsoft Windows 11 22h2: before 10.0.22621.3296 (fixed in 10.0.22621.3296)
  • Microsoft Windows 11 23h2: before 10.0.22631.3296 (fixed in 10.0.22631.3296)
  • Microsoft Windows Server 2022: before 10.0.20348.2340 (fixed in 10.0.20348.2340)
  • Microsoft Windows Server 2022 23h2: before 10.0.25398.763 (fixed in 10.0.25398.763)

Published 2024-03-12. Last modified 2026-06-17.