CVE-2021-24112CriticalCVSS 8.1
.NET Core Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? When a .NET application utilizing libgdiplus on a non-Windows system accepts input, an attacker could send a specially crafted request that could result in remote code execution. Does this vulnerability affect applications running on Windows? No, Windows utilizes GDI+ to process these requests, and is not affected by this vulnerability.
🎯 Affected products5
- .NET 5.0
- .NET Core 2.1
- .NET Core 3.1
- Mono 6.12.0
- Visual Studio 2019 for Mac
✅ Remediation
KBRelease Notes (Security Update)
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24112
- patchhttps://visualstudio.microsoft.com/vs/mac/
- patchhttps://www.mono-project.com/download/stable/
- patchhttps://dotnet.microsoft.com/download/dotnet-core/2.1
- patchhttps://dotnet.microsoft.com/download/dotnet-core/3.1
- patchhttps://dotnet.microsoft.com/download/dotnet/5.0