CVE-2011-3414

EXPLOITED

Microsoft .NET Framework <4.0 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2011-3414 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14588
Various Sources x_refsource_misc
http://www.nruns.com/_downloads/advisory28122011.pdf
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-347A.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/903934
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
Various Sources x_refsource_misc
http://www.ocert.org/advisories/ocert-2011-003.html

Scores

EPSS 0.5889
EPSS Percentile 99.0%

Details

VulnCheck KEV 2012-01-17
CWE
CWE-399
Status published
Products (7)
microsoft/windows_7 (3 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008 (4 CPE variants)
microsoft/windows_server_2008 r2
microsoft/windows_vista (2 CPE variants)
microsoft/windows_xp
microsoft/windows_xp sp3 unknown
Published Dec 30, 2011
Tracked Since Feb 18, 2026