CVE-2024-38168

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 13, 2024
Updated: Aug 16, 2024
CWE ID 400

Summary

CVE-2024-38168 is a newly disclosed vulnerability affecting both .NET and Visual Studio. This issue permits an attacker to trigger a denial of service condition by sending malicious requests, causing the targeted applications to crash or become unresponsive. The vulnerability arises from an improper input validation mechanism, enabling potential attackers to manipulate certain functions and exploit the software. The impact of this vulnerability can lead to significant downtime and disruptions to businesses reliant on these applications. Microsoft urges users to apply the relevant patches as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Visual Studio 2022
  • Microsoft .NET Framework

Affected Vendors

  • Microsoft