CVE-2021-31204
published 2021-05-11CVE-2021-31204: .NET and Visual Studio Elevation of Privilege Vulnerability
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.40%
69.4th percentile
.NET and Visual Studio Elevation of Privilege Vulnerability
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.4 | >= 16.0 < publication | publication |
| microsoft | microsoft_visual_studio_2019_version_16.7 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_visual_studio_2019_version_16.9 | >= 15.0.0 < publication | publication |
| microsoft | net | 5.0 – 5.0.5 | — |
| microsoft | net_5.0 | >= 5.0.0 < 5.0.6-servicing.21220.11 | 5.0.6-servicing.21220.11 |
| microsoft | net_core | 3.1 – 3.1.14 | — |
| microsoft | net_core_3.1 | >= 3.1 < 3.1.15-servicing.21214.3 | 3.1.15-servicing.21214.3 |
| microsoft | visual_studio_2019 | — | — |
| microsoft | visual_studio_2019 | >= 16.0 < 16.4.22 | 16.4.22 |
| microsoft | visual_studio_2019 | >= 16.5.0 < 16.7.15 | 16.7.15 |
| microsoft | visual_studio_2019 | >= 16.8.0 < 16.9.5 | 16.9.5 |
| microsoft | visual_studio_2019_for_mac_version_8.9 | >= 8.0 < publication | publication |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.7 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.9 | — | — |
| msrc | net_5.0 | — | — |
| msrc | net_core_3.1 | — | — |
| msrc | visual_studio_2019_for_mac_version_8.9 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET and Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2021-05-11·CVSS 7.3
CVE-2021-31204 [HIGH] .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET Core & Visual Studio: .NET Core & Visual Studio
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://dotnet.microsoft.com/download/dotnet-core/3.1
Reference: https://dotnet.microsoft.com/download/dotnet/5.0
Reference: http://aka.ms/vs/16/release/latest
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.4
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.7
Reference: https://visualstudio.microsoft.com/downloads/
Red Hat
dotnet: .NET Core single-file application privilege escalation
vendor_redhat·2021-05-11·CVSS 7.3
CVE-2021-31204 [HIGH] CWE-273 dotnet: .NET Core single-file application privilege escalation
dotnet: .NET Core single-file application privilege escalation
.NET and Visual Studio Elevation of Privilege Vulnerability
A flaw was found in dotnet. A .NET Core single-file application running with elevated permissions could allow an attacker to gain elevated privileges. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) - Qualys covers 85 Vulnerabilities, 26 Critical | Qualys
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) - Qualys covers 85 Vulnerabilities, 26 Critical | Qualys
### Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
#### Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Co
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4F3VM3RMPE7PNNLLI3BPCSAXITQZCFCA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6M7KL3KTHJVQNRA3CWFUTESQJARQEHSZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FVMWZPF4FR6JPFSNAIDIUDULHZJBVCW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFXJPQUYUITJMV75YN3XIGE3KKN5GOCU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UV4ITB3SUDGR23G7XALUVKFJMZERFUKF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWF25Z3CZ6LYCOHZ7FPSFAQ426JUBUZ4/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31204https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4F3VM3RMPE7PNNLLI3BPCSAXITQZCFCA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6M7KL3KTHJVQNRA3CWFUTESQJARQEHSZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FVMWZPF4FR6JPFSNAIDIUDULHZJBVCW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFXJPQUYUITJMV75YN3XIGE3KKN5GOCU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UV4ITB3SUDGR23G7XALUVKFJMZERFUKF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWF25Z3CZ6LYCOHZ7FPSFAQ426JUBUZ4/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31204
2021-05-11
Published