CVE-2023-38171 – microsoft.native.quic.msquic.openssl
Package
Manager: nuget
Name: microsoft.native.quic.msquic.openssl
Vulnerable Version: >=0 <2.2.3
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.05105 pctl0.89431
Details
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel ### Impact The MsQuic server application or process will crash, resulting in a denial of service. ### Patches The following patch was made: - Don't Allow Version Negotiation Packets for Server Connections - https://github.com/microsoft/msquic/commit/3226cff07d22662f16fc98d605656860e64cd343 ### Workarounds Beyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality.
Metadata
Created: 2023-10-10T21:23:27Z
Modified: 2024-06-03T18:35:09Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-xh5m-8qqp-c5x7/GHSA-xh5m-8qqp-c5x7.json
CWE IDs: ["CWE-400", "CWE-476"]
Alternative ID: GHSA-xh5m-8qqp-c5x7
Finding: F002
Auto approve: 1