CVE-2023-33170HighCVSS 8.1

ASP.NET and Visual Studio Security Feature Bypass Vulnerability

Published
July 11, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition and also to take additional actions prior to exploitation to prepare the target environment.

🎯 Affected products6

  • .NET 6.0
  • .NET 7.0
  • Microsoft Visual Studio 2022 version 17.0
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6

✅ Remediation

KBRelease Notes (Security Update) — fixed build 17.2.17 KBRelease Notes (Security Update) — fixed build 17.0.23 KBRelease Notes (Security Update) — fixed build 17.4.9 KBRelease Notes (Security Update) — fixed build 17.6.5 KB5028705 (Security Update) — fixed build 6.0.20 KB5028706 (Security Update) — fixed build 7.0.9

🔗 References (7)