« Volver al listado

Microsoft

Microsoft .net: vulnerabilidades y CVE

Microsoft .net tiene 123 vulnerabilidades publicadas, 49 de ellas en los últimos 12 meses. 6 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE123
Últimos 12 meses49
Críticas6
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-38180Alta (7.5)14%⚠ Explotación activa8 ago 2023
.NET and Visual Studio Denial of Service Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71328Alta (8.8)0.76%—8 sept 2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69806Alta (7)0.76%—8 sept 2026
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-69439Alta (8.8)0.84%—8 sept 2026
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69304Media (5.9)0.88%—8 sept 2026
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-70354Alta (7.8)0.36%—11 ago 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62909Alta (7.8)0.26%—11 ago 2026
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62902Media (6.5)0.87%—11 ago 2026
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901Alta (7.5)1.2%—11 ago 2026
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62900Media (5.9)0.75%—11 ago 2026
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899Media (5.9)0.75%—11 ago 2026
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62898Alta (7.5)1.0%—11 ago 2026
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897Alta (7)0.37%—11 ago 2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62886Alta (7.8)0.47%—11 ago 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62871Alta (7.8)0.47%—11 ago 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-58641Alta (7.8)0.47%—11 ago 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50659Media (6.5)0.74%—14 jul 2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-50651Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50650Alta (7.8)0.46%—14 jul 2026
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50649Alta (7.8)4.0%—14 jul 2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50648Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50646Alta (7.8)4.0%—14 jul 2026
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50528Alta (8.2)0.61%—14 jul 2026
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50527Alta (7.5)1.2%—14 jul 2026
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50526Media (5.5)0.22%—14 jul 2026
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50525Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50524Alta (7.5)1.2%—14 jul 2026
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47304Crítica (9.8)0.29%—14 jul 2026
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-47303Alta (8.8)0.84%—14 jul 2026
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47300Alta (8.8)0.78%—14 jul 2026
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application29
  2. T1059 Command and Scripting Interpreter18
  3. T1203 Exploitation for Client Execution18
  4. T1499.004 Application or System Exploitation18
  5. T1068 Exploitation for Privilege Escalation8
  6. T1499 Endpoint Denial of Service4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft