CVE-2023-36049
published 2023-11-14CVE-2023-36049: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.51%
95.8th percentile
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_2.0_service_pack_2 | >= 2.0.0 < 3.0.50727.8975 | 3.0.50727.8975 |
| microsoft | microsoft_net_framework_3.0_service_pack_2 | >= 3.0.0 < 3.0.50727.8975 | 3.0.50727.8975 |
| microsoft | microsoft_net_framework_3.5 | >= 3.5.0 < 3.0.50727.8975 | 3.0.50727.8975 |
| microsoft | microsoft_net_framework_3.5.1 | >= 3.5.0 < 3.0.50727.8975 | 3.0.50727.8975 |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | >= 3.0.0.0 < 10.0.14393.6452 | 10.0.14393.6452 |
| microsoft | microsoft_net_framework_3.5_and_4.6_4.6.2 | >= 10.0.0 < 10.0.10240.20308 | 10.0.10240.20308 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 4.7.4076.0 | 4.7.4076.0 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 4.8.4682.0 | 4.8.4682.0 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 4.8.9206.0 | 4.8.9206.0 |
| microsoft | microsoft_net_framework_4.6.2 | >= 4.7.0 < 4.7.4076.0 | 4.7.4076.0 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.4076.0 | 4.7.4076.0 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.4682.0 | 4.8.4682.0 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.22 | 17.2.22 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.14 | 17.4.14 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.10 | 17.6.10 |
| microsoft | microsoft_visual_studio_2022_version_17.7 | >= 17.7.0 < 17.7.7 | 17.7.7 |
| microsoft | net | — | — |
| microsoft | net | >= 6.0.0 < 6.0.25 | 6.0.25 |
| microsoft | net | >= 7.0.0 < 7.0.14 | 7.0.14 |
| microsoft | net_6.0 | >= 6.0.0 < 6.0.25 | 6.0.25 |
| microsoft | net_7.0 | >= 7.0.0 < 7.0.14 | 7.0.14 |
| microsoft | net_8.0 | >= 8.0 < 8.0.0 | 8.0.0 |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_msrc7.6HIGH
vendor_redhat7.6HIGH
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
dotnet6, dotnet7, dotnet8 vulnerabilities
osv·2023-11-15·CVSS 9.8
CVE-2023-36558 [CRITICAL] dotnet6, dotnet7, dotnet8 vulnerabilities
dotnet6, dotnet7, dotnet8 vulnerabilities
Barry Dorrans discovered that .NET did not properly implement certain
security features for Blazor server forms. An attacker could possibly
use this issue to bypass validation, which could trigger unintended
actions. (CVE-2023-36558)
Piotr Bazydlo discovered that .NET did not properly handle untrusted
URIs provided to System.Net.WebRequest.Create. An attacker could possibly
use this issue to inject arbitrary commands to backend FTP servers.
(CVE-2023-36049)
GHSA
Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
ghsa·2023-11-14·CVSS 9.8
CVE-2023-36049 [CRITICAL] CWE-20 Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 7.0 and .NET 8.0 RC2. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
An elevation of privilege vulnerability exists in .NET where untrusted URIs provided to System.Net.WebRequest.Create can be used to inject arbitrary commands to backend FTP servers.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/287
### Mitigation factors
Microsoft has not identifi
OSV
CVE-2023-36049
osv·2023-11-14·CVSS 9.8
CVE-2023-36049 [CRITICAL] CVE-2023-36049
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
OSV
Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
osv·2023-11-14·CVSS 9.8
CVE-2023-36049 [CRITICAL] Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 7.0 and .NET 8.0 RC2. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.
An elevation of privilege vulnerability exists in .NET where untrusted URIs provided to System.Net.WebRequest.Create can be used to inject arbitrary commands to backend FTP servers.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/287
### Mitigation factors
Microsoft has not identifi
CISA ICS
Siemens ST7 ScadaConnect
cisa_ics·2024-06-13·CVSS 7.5
[HIGH] Siemens ST7 ScadaConnect
ICS Advisory
##
Siemens ST7 ScadaConnect
Release DateJune 13, 2024
Alert CodeICSA-24-165-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: ST7 ScadaConnect
- Vulnerabilities: Integer Overflow or Wraparound, Double Free, Improper Certificate Validation, Inefficient Regular Ex
CISA ICS
Siemens Telecontrol Server Basic
cisa_ics·2024-04-11
Siemens Telecontrol Server Basic
ICS Advisory
##
Siemens Telecontrol Server Basic
Release DateApril 11, 2024
Alert CodeICSA-24-102-08
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Telecontrol Server Basic
- Vulnerabilities: Inadequate Encryption Strength, Double Free, Integer Overflow or Wraparound, External Control of File Name or Path, Path Traversal, Improper Input Validation, Missing Encry
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2023-11-15·CVSS 7.6
CVE-2023-36049 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
Barry Dorrans discovered that .NET did not properly implement certain
security features for Blazor server forms. An attacker could possibly
use this issue to bypass validation, which could trigger unintended
actions. (CVE-2023-36558)
Piotr Bazydlo discovered that .NET did not properly handle untrusted
URIs provided to System.Net.WebRequest.Create. An attacker could possibly
use this issue to inject arbitrary commands to backend FTP servers.
(CVE-2023-36049)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: Arbitrary File Write and Deletion Vulnerability: FormatFtpCommand
vendor_redhat·2023-11-14·CVSS 7.6
CVE-2023-36049 [HIGH] CWE-94 dotnet: Arbitrary File Write and Deletion Vulnerability: FormatFtpCommand
dotnet: Arbitrary File Write and Deletion Vulnerability: FormatFtpCommand
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
A vulnerability was found in FormatFtpCommand in the .NET package that may result in a CRLF injection arbitrary file write and deletion.
Statement: The vulnerability identified in FormatFtpCommand within the .NET package presents a moderate severity concern rather than an important one due to several mitigating factors. Firstly, while it allows for CRLF (Carriage Return Line Feed) injection, enabling potential arbitrary file write and deletion, its impact is limited by the context in which it can be exploited. The injection occurs within the FTP command formatting process, requiring an attacker to have authenticated access to the FTP serv
Microsoft
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2023-11-14·CVSS 7.6
CVE-2023-36049 [HIGH] CWE-20 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability an attacker would have to inject arbitrary commands to the FTP server.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability would be access controls on the server, allowing for read or write abilities.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
.NET Framework: .NET Framework
Microsoft: Microsoft
Customer Action Require
No detection rules found.
No public exploits indexed.
Trendmicro
The November 2023 Security Update Review
blogs_trendmicro·2023-11-14·CVSS 8.8
[HIGH] The November 2023 Security Update Review
## The November 2023 Security Update Review
Get the November 2023 security update and review.
By: Zero Day Initiative 2023/11/14 Read time: ( words)
Save to Folio
It’s the penultimate second Tuesday of 2023, and Microsoft and Adobe have released their latest security patches into the crisp, fall air. Take a break from your scheduled activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
C VE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2023-36033
Windows DWM Core Library Elevation of Privilege Vulnerability
Important
7.8
Yes
Yes
EoP
CVE-2023-36036
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Important
7.8
No
Yes
EoP
CVE-2023-36025
Windows SmartSc
Bleepingcomputer
Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws
blogs_bleepingcomputer·2023-11-14·CVSS 7.8
[HIGH] Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws
## Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws
## Lawrence Abrams
16 Elevation of Privilege Vulnerabilities
6 Security Feature Bypass Vulnerabilities
15 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
5 Denial of Service Vulnerabilities
11 Spoofing Vulnerabilities
The total count of 58 flaws does not include 5 Mariner security updates and 20 Microsoft Edge security updates released earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5032190 cumulative update and Windows 10 KB5032189 cumulative update .
## Five zero-days fixed
This month's Patch Tuesday fixes five zero-day vulnerabilities, with three exploited in attacks and three publicl
Trendmicro
The November 2023 Security Update Review
blogs_trendmicro·2023-11-14
The November 2023 Security Update Review
# The November 2023 Security Update Review
Get the November 2023 security update and review.
By: Zero Day Initiative
2023/11/14
Read time: ( words)
Save to Folio
It’s the penultimate second Tuesday of 2023, and Microsoft and Adobe have released their latest security patches into the crisp, fall air. Take a break from your scheduled activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Adobe Patches for November 2023
For November, Adobe released 14 bulletins addressing 76 CVEs in Adobe Acrobat and Reader, ColdFusion, Audition, Premiere Pro, After Effects, Media Encoder, Dimension, Animate, InCopy, InDesign, RoboHelp, FrameMaker Publishing Server, Bridge, and Photoshop. A total of 54 of these bugs
Trendmicro
The November 2023 Security Update Review
blogs_trendmicro·2023-11-14·CVSS 8.8
[HIGH] The November 2023 Security Update Review
## The November 2023 Security Update Review
Get the November 2023 security update and review.
By: Zero Day Initiative Nov 14, 2023 Read time: ( words)
Save to Folio
It’s the penultimate second Tuesday of 2023, and Microsoft and Adobe have released their latest security patches into the crisp, fall air. Take a break from your scheduled activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
C VE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2023-36033
Windows DWM Core Library Elevation of Privilege Vulnerability
Important
7.8
Yes
Yes
EoP
CVE-2023-36036
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Important
7.8
No
Yes
EoP
CVE-2023-36025
Windows Smart
Huntress
CVE-2023-36049 (.NET FTP Injection) Vulnerability: Analysis & Detection | Huntress
blogs_huntress·CVSS 9.8
CVE-2023-36049 [CRITICAL] CVE-2023-36049 (.NET FTP Injection) Vulnerability: Analysis & Detection | Huntress
CVE-2023-36049
Published: 2/20/2025
Written by: Nadine Rozell
## What is CVE-2023-36049 vulnerability?
CVE-2023-36049 is a flaw in the System.Net.WebRequest and System.Net.FtpWebRequest components of the .NET framework.
Specifically, it is an FTP Command Injection vulnerability. If an application accepts a user-supplied URI and uses it to connect to an FTP server, the .NET framework failed to properly validate the input for special characters—specifically Carriage Return (CR) and Line Feed (LF).
By injecting these characters, an attacker can append entirely new FTP commands to the session, executing actions the application developer never intended, such as deleting files or uploading malware.
## When was it discovered?
The vulnerability was publicly disclosed and patched by Microso
2023-11-14
Published