Microsoft QUIC DoS via malformed QUIC packets
CVE-2024-26190 Published on March 12, 2024

Microsoft QUIC Denial of Service Vulnerability
Microsoft QUIC Denial of Service Vulnerability

Github Repository Vendor Advisory NVD

Weakness Type

What is a Resource Exhaustion Vulnerability?

The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVE-2024-26190 has been classified to as a Resource Exhaustion vulnerability or weakness.


Products Associated with CVE-2024-26190

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2024-26190 are published in these products:

 
 
 
 
 
 
 

Affected Versions

Microsoft Visual Studio 2022 version 17.9: Microsoft Windows Server 2022: Microsoft Windows 11 version 21H2: Microsoft Windows 11 version 22H2: Microsoft Windows 11 version 22H3: Microsoft Windows 11 Version 23H2: Microsoft Windows Server 2022, 23H2 Edition (Server Core installation): Microsoft PowerShell 7.3: Microsoft PowerShell 7.4: Microsoft Visual Studio 2022 version 17.4: Microsoft Visual Studio 2022 version 17.6: Microsoft Visual Studio 2022 version 17.8: Microsoft .NET 7.0: Microsoft .NET 8.0:

Vulnerable Packages

The following package name and versions may be associated with CVE-2024-26190

Package Manager Vulnerable Package Versions Fixed In
nuget Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.3.0, < 2.3.5 2.3.5
nuget Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.2.0, < 2.2.7 2.2.7
nuget Microsoft.Native.Quic.MsQuic.Schannel < 2.1.12 2.1.12
nuget Microsoft.Native.Quic.MsQuic.Schannel >= 2.3.0, < 2.3.5 2.3.5
nuget Microsoft.Native.Quic.MsQuic.Schannel >= 2.2.0, < 2.2.7 2.2.7
nuget Microsoft.Native.Quic.MsQuic.OpenSSL < 2.1.12 2.1.12

Exploit Probability

EPSS
0.62%
Percentile
69.73%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.