← Vulnerability feed

Vulnerability record · CVE-2023-38180 · published 8 August 2023

CVE-2023-38180: Microsoft .NET and Visual Studio uncontrolled resource consumption DoS

Microsoft · .Net

CVE-2023-38180 is a denial-of-service flaw in Microsoft .NET, ASP.NET Core and Visual Studio 2022, classified as uncontrolled resource consumption (CWE-400). The record gives no technical detail on the specific mechanism, but the network-reachable, unauthenticated nature makes it a practical availability risk for exposed services.

7.5 CVSS 3.1 High CISA KEV since 9 Aug 2023 EPSS 14% · top 3.6% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
5References
10 Aug 2026Last modified by NVD

Description

.NET and Visual Studio Denial of Service Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 7.5 with network, unauthenticated reachability plus CISA KEV listing and a high EPSS percentile make this an urgent availability threat despite thin technical detail.

What it is

CVE-2023-38180 is a denial-of-service flaw in Microsoft .NET, ASP.NET Core and Visual Studio 2022, classified as uncontrolled resource consumption (CWE-400). The record gives no technical detail on the specific mechanism, but the network-reachable, unauthenticated nature makes it a practical availability risk for exposed services.

Impact

An attacker can degrade or exhaust resources, causing denial of service on affected .NET or ASP.NET Core workloads. No confidentiality or integrity impact is indicated by the CVSS vector.

Attack surface

Reachable over the network per the CVSS vector (AV:N) with no privileges (PR:N) and no user interaction (UI:N). Any internet- or network-exposed .NET/ASP.NET Core endpoint built on an unpatched runtime is in scope.

Exploitation

It is listed in CISA KEV with a 2023-08-30 remediation due date, indicating known exploitation, and EPSS is 0.14016 (96th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the Microsoft MSRC updates for .NET, ASP.NET Core and Visual Studio 2022 immediately, per the vendor advisory.
  • Update Fedora packages using the referenced package-announce advisories.
  • If patching cannot be completed by the KEV due date, restrict network exposure of affected .NET/ASP.NET Core services or discontinue use as CISA directs.
  • Add rate limiting and resource caps in front of exposed .NET endpoints to blunt resource-exhaustion attempts.
  • Track KEV remediation deadlines and verify patched runtime versions across all deployments.

Detection

  • Monitor .NET/ASP.NET Core hosts for abnormal CPU, memory or thread-pool exhaustion and request-rate spikes.
  • Alert on sudden latency increases or 5xx/timeout surges from .NET services.
  • Review process and connection counts on .NET application servers for sustained anomalies.
  • Correlate spikes with inbound request patterns to identify deliberate resource-exhaustion traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-38180 to the Known Exploited Vulnerabilities catalog on 9 August 2023 as "Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 30 August 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38180 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2023-38180), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.