CVE-2023-35390

CWE-77Command Injection10 documents7 sources
Severity
7.8HIGH
EPSS
2.0%
top 16.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateAug 10

Description

.NET and Visual Studio Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

NVDmicrosoft/visual_studio_202217.2.017.2.18+2
NVDmicrosoft/.net6.0.06.0.21+1

Patches

🔴Vulnerability Details

5
OSV
dotnet6, dotnet7 vulnerabilities2023-08-10
OSV
.NET Remote Code Execution Vulnerability2023-08-09
GHSA
.NET Remote Code Execution Vulnerability2023-08-09
CVEList
.NET and Visual Studio Remote Code Execution Vulnerability2023-08-08
OSV
CVE-2023-353902023-08-08

📋Vendor Advisories

4
Ubuntu
.NET vulnerabilities2023-08-10
Ubuntu
.NET vulnerabilities2023-08-08
Microsoft
.NET and Visual Studio Remote Code Execution Vulnerability2023-08-08
Red Hat
dotnet: RCE under dotnet commands2023-08-08
CVE-2023-35390 (HIGH CVSS 7.8) | .NET and Visual Studio Remote Code | cvebase.io