Important EPSS 0.06558 📢 Publicly disclosed 2018-09 archive

Executive Summary

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an application that is leveraging System.IO.Pipelines. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by providing specially crafted requests to the application. The update addresses the vulnerability by correcting how System.IO.Pipelines handles requests.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Denial of Service
Released Sep 11 2018
Last Updated Sep 11 2018
Publicly Disclosed Yes
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.06558 — 0.932 percentile

EPSS Score

0.06558
probability of exploitation in the next 30 days
0.932 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

3 affected products
Product KB Article Severity Impact Restart Required
.NET Core 2.1 Release Notes (Security Update) Important Denial of Service Yes
ASP.NET Core 2.1 Release Notes (Security Update) Important Denial of Service Yes
System.IO.Pipelines Release Notes (Security Update) Important Denial of Service Yes

Patches

1 patch
Article Type Restart
Release Notes Security Update Yes

Known Exploits

Acknowledgments

None