Vulnerability record · CVE-2011-3414 · published 30 December 2011
CVE-2011-3414: ASP.NET HashTable hash collision denial of service
Microsoft · Windows 7
The CaseInsensitiveHashProvider.getHashCode function in the ASP.NET HashTable implementation computes hash values for form parameters without limiting predictable hash collisions. Remote attackers can send many crafted parameters to force excessive hash collision handling, consuming CPU and denying service. The flaw affects Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0.
Description
The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityRemote unauthenticated denial of service with high EPSS and a vendor patch available, though no confirmed exploitation in KEV.
What it is
The CaseInsensitiveHashProvider.getHashCode function in the ASP.NET HashTable implementation computes hash values for form parameters without limiting predictable hash collisions. Remote attackers can send many crafted parameters to force excessive hash collision handling, consuming CPU and denying service. The flaw affects Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0.
Impact
An attacker can cause a denial of service by driving CPU consumption on the target ASP.NET application, making it unavailable to legitimate users. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable remotely over the network via HTTP requests carrying crafted form parameters; no authentication is required per the CVSS vector AV:N/AC:L/Au:N. No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.57687, 99.039th percentile), and references include US-CERT and CERT/CC advisories, but the record does not confirm active exploitation.
What to do
- Apply Microsoft security update MS11-100 for the affected .NET Framework versions.
- Upgrade to a supported .NET Framework release that includes the hash collision fix.
- Limit or reject excessive form parameters at the web server or application layer where feasible.
- Monitor and rate-limit suspicious request patterns that submit unusually large numbers of parameters.
Detection
- Alert on HTTP requests with abnormally high parameter counts or unusually long parameter strings.
- Monitor ASP.NET worker process CPU spikes correlated with parameter-heavy POST requests.
- Review web server logs for repeated requests from a single source with large parameter payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3414 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3414), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.