CVE-2021-34485HighCVSS 5.0

.NET Core and Visual Studio Information Disclosure Vulnerability

Published
August 10, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the contents of a specific dump file. The attacker needs to have local access to the target system and the dump file needs to be created in a specific way by a target on that same system.

🎯 Affected products10

  • .NET 5.0
  • .NET Core 2.1
  • .NET Core 3.1
  • Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
  • Microsoft Visual Studio 2019 version 16.10 (includes 16.0 - 16.9)
  • Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
  • Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
  • Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
  • PowerShell 7.0
  • PowerShell 7.1

✅ Remediation

KBRelease Notes (Security Update) — fixed build 15.9.38 KBRelease Notes (Security Update) — fixed build 16.4.25 KBRelease Notes (Security Update) — fixed build 16.7.18 KBRelease Notes (Security Update) — fixed build 16.9.10 KBRelease Notes (Security Update) — fixed build 16.10.5 KBRelease Notes (Security Update) — fixed build 7.1.4 KBRelease Notes (Security Update) — fixed build 7.0.7 KBRelease Notes (Security Update) — fixed build 2.1.30 KBRelease Notes (Security Update) — fixed build 3.1.18 KBRelease Notes (Security Update) — fixed build 5.0.9

🔗 References (17)