CVE-2023-33135
published 2023-06-14CVE-2023-33135: .NET and Visual Studio Elevation of Privilege Vulnerability
PriorityP336high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
1.00%
58.9th percentile
.NET and Visual Studio Elevation of Privilege Vulnerability
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2022_version_17.0 | >= 17.0.0 < 17.0.22 | 17.0.22 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.16 | 17.2.16 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.8 | 17.4.8 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.3 | 17.6.3 |
| microsoft | net | >= 6.0.0 < 6.0.18 | 6.0.18 |
| microsoft | net | >= 7.0.0 < 7.0.7 | 7.0.7 |
| microsoft | net_6.0 | >= 6.0.0 < 6.0.18 | 6.0.18 |
| microsoft | net_7.0 | >= 7.0.0 < 7.0.7 | 7.0.7 |
| microsoft | visual_studio_2022 | >= 17.0 < 17.0.22 | 17.0.22 |
| microsoft | visual_studio_2022 | >= 17.2 < 17.2.16 | 17.2.16 |
| microsoft | visual_studio_2022 | >= 17.4 < 17.4.8 | 17.4.8 |
| microsoft | visual_studio_2022 | >= 17.6 < 17.6.3 | 17.6.3 |
| msrc | microsoft_visual_studio_2022_version_17.0 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.2 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.4 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.6 | — | — |
| msrc | net_6.0 | — | — |
| msrc | net_7.0 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens ST7 ScadaConnect
cisa_ics·2024-06-13·CVSS 7.5
[HIGH] Siemens ST7 ScadaConnect
ICS Advisory
##
Siemens ST7 ScadaConnect
Release DateJune 13, 2024
Alert CodeICSA-24-165-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: ST7 ScadaConnect
- Vulnerabilities: Integer Overflow or Wraparound, Double Free, Improper Certificate Validation, Inefficient Regular Ex
CISA ICS
Siemens PNI
cisa_ics·2023-11-16·CVSS 5.5
[MEDIUM] Siemens PNI
ICS Advisory
##
Siemens PNI
Release DateNovember 16, 2023
Alert CodeICSA-23-320-12
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC PNI
- Vulnerabilities: Improper Input Validation, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution, a denial-of-service condi
Red Hat
dotnet: Elevation of Privilege - dotnet tool restore command Local Privilege Escalation Vulnerability
vendor_redhat·2023-06-14·CVSS 7.3
CVE-2023-33135 [HIGH] dotnet: Elevation of Privilege - dotnet tool restore command Local Privilege Escalation Vulnerability
dotnet: Elevation of Privilege - dotnet tool restore command Local Privilege Escalation Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
A vulnerability was found in dotnet. This issue may allow local privilege escalation through the dotnet tool restore command.
Package: rh-dotnet60 (.NET 6.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet31-dotnet (.NET Core 3.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet50-dotnet (.NET Core 5.0 on Red Hat Enterprise Linux) - Not affected
Package: dotnet6.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet7.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet6.0 (Red Hat Enterprise Linux 9) - Not affected
Package: dotnet7.0 (Red Hat Enterprise Linux 9) - Not affected
Microsoft
.NET and Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2023-06-13·CVSS 7.3
CVE-2023-33135 [HIGH] .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send the user a malicious file and convince them to open it.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
Low-privilege attackers who successfully exploited the vulnerability could potentially write malicious configurations and download malicious files.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?
An authorized attacker must send the user a malicious file and convince the user to open it.
.NET and Visual Studio: .NET and Visual Studio
M
GHSA
GHSA-57cj-jpx9-frf8
ghsa_unreviewed·2023-06-14
CVE-2023-33135 [HIGH] GHSA-57cj-jpx9-frf8
.NET and Visual Studio Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-14
Published