Exploitation Summary
CVE-2011-3414 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14588
Various Sources x_refsource_misc
http://www.nruns.com/_downloads/advisory28122011.pdf
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-347A.html
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-100
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/903934
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
Various Sources x_refsource_misc
http://www.ocert.org/advisories/ocert-2011-003.html
Scores
EPSS
0.5889
EPSS Percentile
99.0%
Details
VulnCheck KEV
2012-01-17
CWE
CWE-399
Status
published
Products (7)
microsoft/windows_7
(3 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008
(4 CPE variants)
microsoft/windows_server_2008
r2
microsoft/windows_vista
(2 CPE variants)
microsoft/windows_xp
microsoft/windows_xp
sp3 unknown
Published
Dec 30, 2011
Tracked Since
Feb 18, 2026