CVE-2023-21808
published 2023-02-14CVE-2023-21808: .NET and Visual Studio Remote Code Execution Vulnerability
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.15%
63.5th percentile
.NET and Visual Studio Remote Code Execution Vulnerability
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 6.0.0 < 6.0.14 | 6.0.14 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 7.0.0 < 7.0.3 | 7.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 6.0.0 < 6.0.14 | 6.0.14 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 7.0.0 < 7.0.3 | 7.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 6.0.0 < 6.0.14 | 6.0.14 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 7.0.0 < 7.0.3 | 7.0.3 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 6.0.0 < 6.0.14 | 6.0.14 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 7.0.0 < 7.0.3 | 7.0.3 |
| microsoft | microsoft_net_framework_3.5_and_4.6.2 | >= 4.7.0 < 10.0.10240.19747 | 10.0.10240.19747 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 10.0.04038.03 | 10.0.04038.03 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 10.0.04614.06 | 10.0.04614.06 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 10.0.09139.02 | 10.0.09139.02 |
| microsoft | microsoft_net_framework_4.6.2 | >= 4.7.0 < 4.7.04038.06 | 4.7.04038.06 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.04614.08 | 4.7.04614.08 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.04614.05 | 4.8.04614.05 |
| microsoft | microsoft_visual_studio_2013_update_5 | >= 12.0.0 < 12.0.40700.0 | 12.0.40700.0 |
| microsoft | microsoft_visual_studio_2015_update_3 | >= 14.0.0 < 14.0.27555.0 | 14.0.27555.0 |
| microsoft | microsoft_visual_studio_2017_version_15.9 | >= 15.9.0 < 15.9.52 | 15.9.52 |
| microsoft | microsoft_visual_studio_2019_version_16.11 | >= 16.11.0 < 16.11.24 | 16.11.24 |
| microsoft | microsoft_visual_studio_2022_version_17.0 | >= 17.0.0 < 17.0.19 | 17.0.19 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.13 | 17.2.13 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.5 | 17.4.5 |
| microsoft | net | — | — |
| microsoft | net | — | — |
| microsoft | net_6.0 | >= 6.0.0 < 6.0.14 | 6.0.14 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.8HIGH
osv7.8HIGH
vendor_msrc8.4HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens ST7 ScadaConnect
cisa_ics·2024-06-13·CVSS 7.5
[HIGH] Siemens ST7 ScadaConnect
ICS Advisory
##
Siemens ST7 ScadaConnect
Release DateJune 13, 2024
Alert CodeICSA-24-165-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: ST7 ScadaConnect
- Vulnerabilities: Integer Overflow or Wraparound, Double Free, Improper Certificate Validation, Inefficient Regular Ex
CISA ICS
Siemens PNI
cisa_ics·2023-11-16·CVSS 5.5
[MEDIUM] Siemens PNI
ICS Advisory
##
Siemens PNI
Release DateNovember 16, 2023
Alert CodeICSA-23-320-12
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC PNI
- Vulnerabilities: Improper Input Validation, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution, a denial-of-service condi
Microsoft
.NET and Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2023-02-14·CVSS 8.4
CVE-2023-21808 [HIGH] CWE-416 .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.
FAQ: According to the CVSS metrics, there are multiple scores. Why does the CVE have different scores and different severities for different products?
There are different scores depending on the product due to the way symbols are read and parsed. Visual Studio has the ability to automatically query
Red Hat
dotnet: Remote code execution via debugging symbols
vendor_redhat·2023-02-14·CVSS 7.8
CVE-2023-21808 [HIGH] CWE-20 dotnet: Remote code execution via debugging symbols
dotnet: Remote code execution via debugging symbols
.NET and Visual Studio Remote Code Execution Vulnerability
A vulnerability exists in how dotnet reads debugging symbols. Reading a malicious symbols file may result in remote code execution.
Statement: This issue does not affect the dotnet package as shipped with Red Hat Enterprise Linux 8 and 9.
Package: dotnet3.1 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet6.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet7.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet6.0 (Red Hat Enterprise Linux 9) - Not affected
Package: dotnet7.0 (Red Hat Enterprise Linux 9) - Not affected
GHSA
.NET Remote Code Execution Vulnerability
ghsa·2023-02-14·CVSS 7.8
CVE-2023-21808 [HIGH] CWE-416 .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2023-21808: .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in how .NET reads debugging symbols, where reading a malicious symbols file may result in remote code execution.
## Discussion
Discussion for this issue can be found at https://github.com/dotnet/runtime/issues/82112
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected software
* Any .NET 7.0 application running on .NET 7
OSV
.NET Remote Code Execution Vulnerability
osv·2023-02-14·CVSS 7.8
CVE-2023-21808 [HIGH] .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2023-21808: .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in how .NET reads debugging symbols, where reading a malicious symbols file may result in remote code execution.
## Discussion
Discussion for this issue can be found at https://github.com/dotnet/runtime/issues/82112
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected software
* Any .NET 7.0 application running on .NET 7
No detection rules found.
No public exploits indexed.
Qualys
The February 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-02-15
The February 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for February2023
Adobe Patches for February2023
Notable and Critical Microsoft Vulnerabilities Patched
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft and Adobe have released several monthly security fixes and updates for their products. Let’s take a look at the highlights of this month’s Patch Tuesday as we review and discuss the security updates.
## Microsoft Patches for February 2023
Microsoft has patched 79 vulnerabilities this month, in
Qualys
The February 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-02-15
The February 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for February2023
- Adobe Patches for February2023
- Notable and Critical Microsoft Vulnerabilities Patched
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft and Adobe have released several monthly security fixes and updates for their products. Let’s take a look at the highlights of this month’s Patch Tuesday as we review and discuss the security updates.
## Microsoft Patches for February 2023
Microsoft has patched 79 vulnerabilities t
Talos
Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-02-14·CVSS 9.8
CVE-2023-21823 [CRITICAL] Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 73 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical”, 64 are classified as “Important”, one vulnerability is classified as “Moderate.”
According to Microsoft none of the vulnerabilities has been publicly disclosed before Patch Tuesday and only three vulnerabilities were seen in the wild. The most serious one is CVE-2023-21823 a Windows Graphics Component Remote Code Execution Vulnerability. Followed by CVE-2023-21715 a Microsoft Publisher Security Features Bypass Vulnerability which we are describing below and CVE-2023-23376 a local Windows Common Log File System Driver Elevation of Privilege Vulnerability.
Three of the most “Critical“ vulnerabilities, which Microsoft considers to be “more likel
Talos
Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-02-14·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 73 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical”, 64 are classified as “Important”, one vulnerability is classified as “Moderate.”
According to Microsoft none of the vulnerabilities has been publicly disclosed before Patch Tuesday and only three vulnerabilities were seen in the wild. The most serious one is CVE-2023-21823 a Windows Graphics Component Remote Code Execution Vulnerability. Followed by CVE-2023-21715 a Microsoft Publisher Security Features Bypass Vulnerability which we are describing below and CVE-2023-23376 a local Windows Common Log File System Driver Elevation of Privilege Vulnerability.
2023-02-14
Published