CVE-2023-24897

Severity
7.8HIGH
EPSS
2.0%
top 16.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14

Description

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages29 packages

NVDmicrosoft/visual_studio_201715.915.9.55+1
NVDmicrosoft/visual_studio_201916.1116.11.27+1
NVDmicrosoft/visual_studio_202217.017.0.22+3
CVEListV5microsoft/microsoft_visual_studio_2013_update_512.0.012.0.40700.0
CVEListV5microsoft/microsoft_visual_studio_2015_update_314.0.014.0.27555.0

Patches

🔴Vulnerability Details

3
CVEList
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability2023-06-14
GHSA
.NET Remote Code Execution Vulnerability2023-06-14
OSV
.NET Remote Code Execution Vulnerability2023-06-14

📋Vendor Advisories

2
Red Hat
dotnet: RemoteCodeExecution - Out-of-bounds write when loading PDB type records in msdia140.dll used by Visual Studio2023-06-14
Microsoft
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability2023-06-13
CVE-2023-24897 (HIGH CVSS 7.8) | cvebase.io