cbcvebase.
CVE-2023-28260
published 2023-04-11

CVE-2023-28260: .NET DLL Hijacking Remote Code Execution Vulnerability

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
.NET DLL Hijacking Remote Code Execution Vulnerability

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft.netcore.app.runtime.win-arm>= 6.0.0 < 6.0.166.0.16
microsoftmicrosoft.netcore.app.runtime.win-arm>= 7.0.0 < 7.0.57.0.5
microsoftmicrosoft.netcore.app.runtime.win-arm64>= 6.0.0 < 6.0.166.0.16
microsoftmicrosoft.netcore.app.runtime.win-arm64>= 7.0.0 < 7.0.57.0.5
microsoftmicrosoft.netcore.app.runtime.win-x64>= 6.0.0 < 6.0.166.0.16
microsoftmicrosoft.netcore.app.runtime.win-x64>= 7.0.0 < 7.0.57.0.5
microsoftmicrosoft.netcore.app.runtime.win-x86>= 6.0.0 < 6.0.166.0.16
microsoftmicrosoft.netcore.app.runtime.win-x86>= 7.0.0 < 7.0.57.0.5
microsoftmicrosoft_visual_studio_2022_version_17.0>= 17.0.0 < 17.0.2117.0.21
microsoftmicrosoft_visual_studio_2022_version_17.2>= 17.2.0 < 17.2.1517.2.15
microsoftmicrosoft_visual_studio_2022_version_17.4>= 17.4.0 < 17.4.717.4.7
microsoftmicrosoft_visual_studio_2022_version_17.5>= 17.5.0 < 17.5.417.5.4
microsoftnet>= 6.0.0 < 6.0.166.0.16
microsoftnet>= 7.0.0 < 7.0.57.0.5
microsoftnet_6.0>= 6.0.0 < 6.0.166.0.16
microsoftnet_7.0>= 7.0.0 < 7.0.57.0.5
microsoftpowershell_7.2>= 7.2.0 < 7.2.117.2.11
microsoftpowershell_7.3>= 7.3.0 < 7.3.47.3.4
microsoftvisual_studio_2022>= 17.0 < 17.0.2117.0.21
microsoftvisual_studio_2022>= 17.2 < 17.2.1517.2.15
microsoftvisual_studio_2022>= 17.4 < 17.4.717.4.7
microsoftvisual_studio_2022>= 17.5 < 17.5.417.5.4
msrcmicrosoft_visual_studio_2022_version_17.0
msrcmicrosoft_visual_studio_2022_version_17.2
msrcmicrosoft_visual_studio_2022_version_17.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.8HIGH
osv7.8HIGH