CVE-2023-36759
published 2023-09-12CVE-2023-36759: Visual Studio Elevation of Privilege Vulnerability
PriorityP428medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.53%
41.1th percentile
Visual Studio Elevation of Privilege Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2019_version_16.11 | >= 16.11.0 < 16.11.30 | 16.11.30 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.19 | 17.2.19 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.11 | 17.4.11 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.7 | 17.6.7 |
| microsoft | microsoft_visual_studio_2022_version_17.7 | >= 17.7.0 < 17.7.4 | 17.7.4 |
| microsoft | visual_studio_2019 | >= 16.0 < 16.11.30 | 16.11.30 |
| microsoft | visual_studio_2022 | >= 17.2.0 < 17.2.19 | 17.2.19 |
| microsoft | visual_studio_2022 | >= 17.4.0 < 17.4.11 | 17.4.11 |
| microsoft | visual_studio_2022 | >= 17.6.0 < 17.6.7 | 17.6.7 |
| microsoft | visual_studio_2022 | >= 17.7.0 < 17.7.4 | 17.7.4 |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.2 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.4 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.6 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.7 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-724g-5w99-h7cw: Visual Studio Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-09-12
CVE-2023-36759 [MEDIUM] GHSA-724g-5w99-h7cw: Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Microsoft
Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2023-09-12·CVSS 6.7
CVE-2023-36759 [MEDIUM] CWE-822 Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
A domain user could use this vulnerability to elevate privileges to SYSTEM assigned integrity level.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authenticated attacker must send the victim a malicious file and convince them to open it.
Visual Studio: Visual Studio
Microso
No detection rules found.
No public exploits indexed.
2023-09-12
Published