NuGet Client Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Are any other products affected by this vulnerability? Yes. See the following list of affected versions of NuGet.exe, NuGet.Commands, NuGet.CommandLine, and NuGet.Protocol. Customers using any of these affected versions please see for information about how to fix the vulnerability. Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 6.3.0 version or earlier Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 6.2.1 version or earlier Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 6.0.2 version or earlier Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 5.11.2 version or earlier Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 5.9.2 version or earlier Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 5.7.2 version or earlier Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol 4.9.5 version or earlier
What privileges could be gained by an attacker who successfully exploited the vulnerability? The attacker would gain the rights of the user that is running the affected application.
🎯 Affected products8
- .NET 6.0
- .NET Core 3.1
- Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
- Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
- Microsoft Visual Studio 2022 version 17.0
- Microsoft Visual Studio 2022 version 17.2
- Microsoft Visual Studio 2022 version 17.3
- Visual Studio 2022 for Mac version 17.3
✅ Remediation
KB5019351 (Security Update) — fixed build 6.0.10 KB5019349 (Security Update) — fixed build 3.1.30 KBRelease Notes (Security Update) — fixed build 17.2.9 KBRelease Notes (Security Update) — fixed build 16.11.20 KBRelease Notes (Security Update) — fixed build 16.9.26 KBRelease Notes (Security Update) — fixed build 17.0.15 KBRelease Notes (Security Update) — fixed build 17.3.6 KBRelease Notes (Security Update) — fixed build 17.3.7
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41032
- patchhttps://dotnet.microsoft.com/download/dotnet/6.0
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/3.1
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.2
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.11
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.9
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.0
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.3
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio Mac 2022