CVE-2023-33135HighCVSS 7.3

.NET and Visual Studio Elevation of Privilege Vulnerability

Published
June 13, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker must send the user a malicious file and convince them to open it.

What privileges could be gained by an attacker who successfully exploited the vulnerability? Low-privilege attackers who successfully exploited the vulnerability could potentially write malicious configurations and download malicious files.

According to the CVSS metric, user interaction is required (UI:R) and privileges required  is low (PR:L). What does that mean for this vulnerability? An authorized attacker must send the user a malicious file and convince the user to open it.

🎯 Affected products6

  • .NET 6.0
  • .NET 7.0
  • Microsoft Visual Studio 2022 version 17.0
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6

✅ Remediation

KB5027797 (Security Update) — fixed build 6.0.18 KB5027798 (Security Update) — fixed build 7.0.7 KBRelease Notes (Security Update) — fixed build 17.2.16 KBRelease Notes (Security Update) — fixed build 17.0.22 KBRelease Notes (Security Update) — fixed build 17.4.8 KBRelease Notes (Security Update) — fixed build 17.6.3

🔗 References (12)