CVE-2023-21808

CWE-416Use After Free6 documents6 sources
Severity
7.8HIGH
EPSS
1.3%
top 20.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

.NET and Visual Studio Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages26 packages

NVDmicrosoft/visual_studio_201715.015.9.51
NVDmicrosoft/visual_studio_201916.016.11.24
CVEListV5microsoft/microsoft_visual_studio_2013_update_512.0.012.0.40700.0
CVEListV5microsoft/microsoft_visual_studio_2015_update_314.0.014.0.27555.0

Patches

🔴Vulnerability Details

3
CVEList
.NET and Visual Studio Remote Code Execution Vulnerability2023-02-14
GHSA
.NET Remote Code Execution Vulnerability2023-02-14
OSV
.NET Remote Code Execution Vulnerability2023-02-14

📋Vendor Advisories

2
Microsoft
.NET and Visual Studio Remote Code Execution Vulnerability2023-02-14
Red Hat
dotnet: Remote code execution via debugging symbols2023-02-14
CVE-2023-21808 (HIGH CVSS 7.8) | .NET and Visual Studio Remote Code | cvebase.io