Microsoft is releasing this security advisory to provide information about a vulnerability in System.Security.Cryptography.Xml. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in EncryptedXml class where uncontrolled resource consumption can give an attacker to the ability to perform a Denial of Service attack.
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/389
The vulnerability affects any Microsoft .NET project if it uses any of affected packages versions listed below
Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.xml | >=10.0.0, <=10.0.5; | 10.0.6
Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.xml | >=9.0.0, <=9.0.14; | 9.0.15
Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- System.Security.Cryptography.xml | >=8.0.0, <=8.0.2; | 8.0.3
If...
10.0.68.0.39.0.15Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:NA:H7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H