.NET January 2023 Updates – .NET 7.0.2, .NET 6.0.13

Dominique Whittaker

Today, we are releasing the .NET January 2023 Updates. These updates contain security and non-security improvements. Your app may be vulnerable if you have not deployed a recent .NET update.

You can download 7.0.2 and 6.0.13 versions for Windows, macOS, and Linux, for x86, x64, Arm32, and Arm64.


CVE-2023-21538 – .NET Denial of Service Vulnerability

Microsoft is releasing this security advisory to provide information about a vulnerability in.NET 6.0.. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulnerability exists in .NET 6.0 where a malicious client could cause a stack overflow which may result in a denial of service attack when an attacker sends an invalid request to an exposed endpoint.

Visual Studio

See release notes for Visual Studio compatibility for .NET 7.0 and .NET 6.0.