PT-2022-4632 · Microsoft+5 · Visual Studio+8

Published

2022-03-08

·

Updated

2026-05-27

·

CVE-2022-24512

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions .NET versions prior to 6.0.3 .NET 5.0 versions prior to 5.0.15 .NET Core 3.1 versions prior to 3.1.23
Description The issue is related to a buffer overflow due to unchecked input data, which can allow a remote attacker to execute arbitrary code. This is a Remote Code Execution vulnerability in .NET and Visual Studio.
Recommendations For .NET 6.0, update to Runtime 6.0.3 or SDK 6.0.103 (for Visual Studio 2019 v17.0) or SDK 6.0.201 (for Visual Studio 2019 V17.1). For .NET 5.0, update to Runtime 5.0.15 or SDK 5.0.406 (for Visual Studio 2019 v16.11) or SDK 5.0.212 (for Visual Studio 2019 V16.9). For .NET Core 3.1, update to Runtime 3.1.23 or SDK 3.1.417 (for Visual Studio 2019 v16.7). Updates are also available from Microsoft Update, accessible by searching "Check for updates" in Windows search or through Settings, Update & Security, and then clicking Check for Updates.

Fix

RCE

Code Injection

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0826
ALSA-2022:0827
ALSA-2022:0830
ALT-PU-2022-1619
ALT-PU-2022-1620
ALT-PU-2022-1621
ALT-PU-2022-1622
ALT-PU-2022-1627
ALT-PU-2022-1628
ALT-PU-2022-1629
ALT-PU-2022-2415
ALT-PU-2022-2416
ALT-PU-2023-1307
ALT-PU-2023-1308
ALT-PU-2023-1464
ALT-PU-2023-1465
ALT-PU-2023-4713
ALT-PU-2025-2023
BDU:2022-05516
BIT-DOTNET-2022-24512
BIT-DOTNET-SDK-2022-24512
BIT-POWERSHELL-2022-24512
CESA-2022_0826
CESA-2022_0827
CESA-2022_0830
CVE-2022-24512
GHSA-C6W8-7MP3-34J9
RHSA-2022:0826
RHSA-2022:0827
RHSA-2022:0828
RHSA-2022:0829
RHSA-2022:0830
RHSA-2022:0832
RHSA-2022_0826
RHSA-2022_0827
RHSA-2022_0830
RLSA-2022:0826
RLSA-2022:0827
RLSA-2022:0830

Affected Products

Alt Linux
Almalinux
Centos
Net
Net Core
Red Hat
Rocky Linux
Visual Studio
Windows