CVE-2021-43877HighCVSS 8.8

ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

Published
December 14, 2021
Last Modified
—

🔗 CVE IDs covered (1)

🎯 Affected products8

  • ASP.NET Core 3.1
  • ASP.NET Core 5.0
  • ASP.NET Core 6.0
  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
  • Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
  • Microsoft Visual Studio 2022 version 17.0
  • Microsoft Visual Studio 2022 version 17.1

✅ Remediation

KBRelease Notes (Security Update) — fixed build 16.7.23 KBRelease Notes (Security Update) — fixed build 16.9.15 KBRelease Notes (Security Update) — fixed build 16.11.8 KBRelease Notes (Security Update) — fixed build 17.0.3 KBRelease Notes (Security Update) — fixed build 3.1.22 KBRelease Notes (Security Update) — fixed build 5.0.13 KBRelease Notes (Security Update) — fixed build 6.0.101 KBRelease Notes (Security Update) — fixed build 17.1.4

🔗 References (9)