Severity
9.8CRITICAL
EPSS
2.1%
top 15.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateNov 15

Description

.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LExploitability: 2.8 | Impact: 4.7

Affected Packages25 packages

Patches

🔴Vulnerability Details

5
OSV
dotnet6, dotnet7, dotnet8 vulnerabilities2023-11-15
GHSA
Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability2023-11-14
CVEList
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability2023-11-14
OSV
CVE-2023-360492023-11-14
OSV
Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability2023-11-14

📋Vendor Advisories

3
Ubuntu
.NET vulnerabilities2023-11-15
Red Hat
dotnet: Arbitrary File Write and Deletion Vulnerability: FormatFtpCommand2023-11-14
Microsoft
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability2023-11-14

🕵️Threat Intelligence

1
Huntress
CVE-2023-36049 (.NET FTP Injection) Vulnerability: Analysis & Detection | Huntress