CVE-2020-8927HighCVSS 6.5

Brotli Library Buffer Overflow Vulnerability

Published
March 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Why is this Google LLC CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in the Brotli library which is consumed by .NET and by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of .NET and Visual Studio are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.

🎯 Affected products10

  • .NET 5.0
  • .NET Core 3.1
  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
  • Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
  • Microsoft Visual Studio 2022 version 17.0
  • Microsoft Visual Studio 2022 version 17.1
  • PowerShell 7.0
  • PowerShell 7.1
  • PowerShell 7.2

✅ Remediation

KBRelease Notes (Security Update) — fixed build 3.1.23 KBRelease Notes (Security Update) — fixed build 5.0.15 KBRelease Notes (Security Update) — fixed build 16.7.26 KBRelease Notes (Security Update) — fixed build 16.9.18 KBRelease Notes (Security Update) — fixed build 16.11.11 KBRelease Notes (Security Update) — fixed build 17.0.7 KBRelease Notes (Security Update) — fixed build 7.2.2 KBRelease Notes (Security Update) — fixed build 7.1.6 KBRelease Notes (Security Update) — fixed build 7.0.9 KBRelease Notes (Security Update) — fixed build 17.1.4

🔗 References (15)