CVE-2023-36788

CWE-94Code Injection6 documents6 sources
Severity
7.8HIGH
EPSS
0.4%
top 40.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12
Latest updateSep 13

Description

.NET Framework Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5microsoft/microsoft_.net_framework_3.53.5.03.0.30729.8957
CVEListV5microsoft/microsoft_.net_framework_3.5.13.5.03.0.30729.8957
CVEListV5microsoft/microsoft_.net_framework_3.5_and_4.84.8.04.8.04667.03
CVEListV5microsoft/microsoft_.net_framework_3.5_and_4.6.24.7.010.0.10240.20162
CVEListV5microsoft/microsoft_.net_framework_3.5_and_4.7.24.7.04.7.04063.05

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mwmx-c24c-vmmg2023-09-12
OSV
CVE-2023-367882023-09-12
CVEList
.NET Framework Remote Code Execution Vulnerability2023-09-12

📋Vendor Advisories

2
Red Hat
dotnet: .NET Framework Remote Code Execution Vulnerability2023-09-13
Microsoft
.NET Framework Remote Code Execution Vulnerability2023-09-12