CVE-2023-38180

HIGH(7.5)KEVElevated Risk

Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability

Description

CVE-2023-38180 is a denial of service vulnerability affecting Microsoft .NET and Visual Studio caused by uncontrolled resource consumption. An unauthenticated attacker can exploit this flaw to cause a denial of service condition in applications built on .NET, ASP.NET Core, or developed with Visual Studio 2022. CISA has added CVE-2023-38180 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. While the EPSS score of 0.88% indicates a relatively lower exploitation probability compared to other KEV entries, the confirmed active exploitation and the widespread use of .NET in enterprise environments make this vulnerability a security concern for organizations relying on Microsoft's development platform.

KEV Information

Vendor
Microsoft
Product
.NET Core and Visual Studio
Date Added
August 9, 2023
Due Date
August 30, 2023
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
microsoft.net>= 6.0.0, < 6.0.21; >= 7.0.0, < 7.0.10
microsoftasp.net core>= 2.1, < 2.1.40
microsoftvisual studio 2022>= 17.2.0, < 17.2.18; >= 17.4.0, < 17.4.10; >= 17.6.0, < 17.6.6
fedoraprojectfedora37; 38

References

Weakness Type

CWE-400: Uncontrolled Resource Consumption

In the context of CVE-2023-38180, the .NET and Visual Studio runtime fails to properly manage resource consumption when processing certain inputs, allowing an attacker to exhaust system resources and cause a denial of service. This uncontrolled resource consumption weakness enables remote attackers to degrade or completely disrupt the availability of applications built on the affected .NET framework.

Learn more: CWE-400 — Uncontrolled Resource Consumption

Impact Analysis

CVE-2023-38180 carries a CVSS v3.1 score of 7.5 (High severity) and primarily impacts the availability of affected systems. The vulnerability is remotely exploitable without physical access, easy to exploit with no special conditions needed, requires no authentication, and demands no user interaction — making it straightforward for attackers to trigger a denial of service. Availability (High): The primary impact is denial of service, where attackers can cause .NET-based applications and services to become unresponsive or crash, disrupting business operations that depend on these applications. Confidentiality and Integrity (None): This vulnerability does not allow data theft or modification — it is purely a denial of service vector. Despite the limited scope to availability only, the ubiquity of .NET and ASP.NET Core in enterprise web applications and services means that a successful exploit can have broad operational impact across an organization's application portfolio.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2023-38180 in the wild by adding it to the Known Exploited Vulnerabilities catalog, with a remediation deadline of August 30, 2023. The EPSS score of 0.88% (75th percentile) suggests that while exploitation is occurring, it is not as widespread as other critical vulnerabilities. Microsoft has published a security update guide with patch information for affected products. No public exploit code is directly tagged in the NVD references, but the KEV listing confirms that functional exploitation methods exist in the wild.

Remediation

  1. Apply vendor mitigations immediately. Follow CISA's required action: apply mitigations per Microsoft's instructions via the Microsoft Security Update Guide, or discontinue use of the product if mitigations are unavailable. The CISA remediation deadline was August 30, 2023.
  2. Update affected Microsoft products to patched versions: apply the latest security updates for .NET, ASP.NET Core, and Visual Studio 2022. Fedora users should also apply the relevant updates distributed through the Fedora package repositories.
  3. Implement rate limiting and resource controls on .NET-based web applications and services to mitigate uncontrolled resource consumption. Configure request size limits, connection timeouts, and concurrent connection limits on web servers hosting ASP.NET Core applications.
  4. Monitor application health and performance for signs of denial of service attacks, including unusual CPU or memory consumption spikes, abnormal request patterns, and application unresponsiveness. Set up alerting on application availability metrics.
  5. Deploy network-level protections such as a web application firewall (WAF) and DDoS mitigation services in front of internet-facing .NET applications to filter malicious traffic before it reaches the application layer.

Technical Details

CVE-2023-38180 exploits an uncontrolled resource consumption weakness (CWE-400) in the .NET runtime and related Microsoft development tools. The vulnerability allows a remote, unauthenticated attacker to send specially crafted requests that cause the .NET application to consume excessive system resources such as CPU, memory, or network bandwidth, ultimately resulting in a denial of service condition. As reflected in the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), the attack is network-based with low complexity, requires no privileges or user interaction, and exclusively impacts availability with no effect on confidentiality or integrity. The affected products span the .NET ecosystem including .NET, ASP.NET Core, and Visual Studio 2022, with the Fedora distribution also distributing affected packages.

Frequently Asked Questions

Is CVE-2023-38180 being actively exploited?

Yes, CVE-2023-38180 is being actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of August 30, 2023. While the EPSS score of 0.88% suggests targeted rather than widespread exploitation, organizations should apply patches immediately.

What products are affected by CVE-2023-38180?

CVE-2023-38180 affects Microsoft .NET, ASP.NET Core, and Visual Studio 2022. The Fedora Linux distribution also packages affected components. All versions prior to the security updates referenced in the Microsoft Security Update Guide are considered vulnerable.

How do I fix CVE-2023-38180?

Apply the security updates from Microsoft via the Microsoft Security Update Guide for .NET, ASP.NET Core, and Visual Studio 2022. Additionally, implement rate limiting and resource controls on .NET applications and deploy network-level protections for internet-facing services. See the Remediation section for detailed steps.

How severe is CVE-2023-38180?

CVE-2023-38180 is rated High severity with a CVSS v3.1 score of 7.5. It ranks in the 75th percentile for exploitation probability (EPSS). While the impact is limited to denial of service (no data theft or modification), the widespread use of .NET in enterprise environments means the operational impact of a successful exploit can be significant.

CVSS Score

7.5
HIGH(7.5)

EPSS Score

EPSS Score14.02%
EPSS Percentile96.3%

Dates

PublishedAugust 8, 2023
Last ModifiedAugust 10, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.