Lucene search

K
githubGitHub Advisory DatabaseGHSA-XH5M-8QQP-C5X7
HistoryOct 10, 2023 - 9:23 p.m.

Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel

2023-10-1021:23:27
CWE-400
CWE-476
GitHub Advisory Database
github.com
26
msquic
denial of service
vulnerability
microsoft.native.quic.msquic.schannel
patches
version negotiation packets

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.8%

Impact

The MsQuic server application or process will crash, resulting in a denial of service.

Patches

The following patch was made:

Workarounds

Beyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality.

Affected configurations

Vulners
Node
microsoftnative.quic.msquic.opensslRange<2.2.3
OR
microsoftnative.quic.msquic.schannelRange<2.2.3
VendorProductVersionCPE
microsoftnative.quic.msquic.openssl*cpe:2.3:a:microsoft:native.quic.msquic.openssl:*:*:*:*:*:*:*:*
microsoftnative.quic.msquic.schannel*cpe:2.3:a:microsoft:native.quic.msquic.schannel:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.8%