PT-2023-1443 · Microsoft +1 · .Net Framework +2

Goodbyeselene

·

Published

2023-02-14

·

Updated

2024-12-13

·

CVE-2023-21808

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Microsoft .NET Framework and .NET (affected versions not specified)

Visual Studio (affected versions not specified)

Description:

The issue is related to insufficient protection of sensitive data during the implementation of debugging code in Microsoft .NET Framework and .NET. It allows a remote attacker to execute arbitrary code, potentially affecting the system.

Recommendations:

For Microsoft .NET Framework and .NET, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

For Visual Studio, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1469
ALT-PU-2023-1470
ALT-PU-2023-4594
ALT-PU-2023-4595
ALT-PU-2024-16792
ALT-PU-2024-16794
BDU:2023-00850
BIT-DOTNET-2023-21808
BIT-DOTNET-SDK-2023-21808
CVE-2023-21808
GHSA-824J-WQM8-89MJ

Affected Products

.Net Framework
Alt Linux
Visual Studio