CVE-2023-24936

10 documents7 sources
Severity
7.5HIGH
EPSS
1.2%
top 21.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateJun 23

Description

.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages36 packages

CVEListV5microsoft/microsoft_.net_framework_3.53.5.03.0.6920.8954; 2.0.50727.8970

Patches

🔴Vulnerability Details

6
OSV
dotnet6, dotnet7 regression2023-06-23
GHSA
.NET Elevation of Privilege Vulnerability2023-06-14
CVEList
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability2023-06-14
OSV
.NET Elevation of Privilege Vulnerability2023-06-14
OSV
CVE-2023-249362023-06-13

📋Vendor Advisories

3
Red Hat
dotnet: Bypass restrictions when deserializing a DataSet or DataTable from XML2023-06-14
Ubuntu
.NET vulnerabilities2023-06-13
Microsoft
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability2023-06-13