← back
CVE-2014-0253observed exploitation

CVE-2014-0253

37Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 39%
from disclosure to weapon
Published on NVDFeb 12
VulnCheckFeb 11
exploitation probability
39%top 2% of all CVEs
observed exploitation
yesVulnCheck
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resource consumption for a (1) stale or (2) closed connection, as exploited in the wild in February 2014, aka "POST Request DoS Vulnerability."
Affected products
n/a · n/a