Vulnerability GHSA-xh5m-8qqp-c5x7
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 years ago
October 10, 2023 at 09:23 PM UTC
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
1.8.0
1.8.0
Summary
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
Details
Impact
The MsQuic server application or process will crash, resulting in a denial of service.
Patches
The following patch was made:
- Don't Allow Version Negotiation Packets for Server Connections - https://github.com/microsoft/msquic/commit/3226cff07d22662f16fc98d605656860e64cd343
Workarounds
Beyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
3 hours ago
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
1.8.0 GHSA-w5f4-fx9m-m4q7
1.8.0 GHSA-w5f4-fx9m-m4q7
Critical
27 days ago
Microsoft QUIC: Remote Code Execution Vulnerability
1.8.0 GHSA-92f5-vc22-8j33
1.8.0 GHSA-92f5-vc22-8j33
Critical
27 days ago
Microsoft QUIC: Remote Code Execution Vulnerability
1.8.0 GHSA-92f5-vc22-8j33
1.8.0 GHSA-92f5-vc22-8j33
Critical
5 months ago
MsQuic has a Remote Elevation of Privilege Vulnerability
1.8.0 GHSA-gvvw-8j96-8g5r
1.8.0 GHSA-gvvw-8j96-8g5r
Critical
5 months ago
MsQuic has a Remote Elevation of Privilege Vulnerability
1.8.0 GHSA-gvvw-8j96-8g5r
1.8.0 GHSA-gvvw-8j96-8g5r
Impacted packages
Timeline
Published
2 years ago
October 10, 2023 at 09:23 PM UTC
Last Modified
2 years ago
June 03, 2024 at 06:46 PM UTC