CVE-2023-36042HighCVSS 6.2
Visual Studio Denial of Service Vulnerability
🔗 CVE IDs covered (1)
🎯 Affected products17
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation)
- Microsoft Visual Studio 2022 version 17.6
- Microsoft Visual Studio 2022 version 17.7
✅ Remediation
KBRelease Notes (Security Update) — fixed build 17.6.10 KBRelease Notes (Security Update) — fixed build 17.7.7 KB5034272 (Security Update) — fixed build 4.8.09214.01 KB5034276 (Security Update) — fixed build 4.8.09214.01 KB5034274 (Security Update) — fixed build 4.8.09214.01 KB5033920 (Security Update) — fixed build 4.8.09214.01 KB5034275 (Security Update) — fixed build 4.8.09214.01 KB5033917 (Security Update) — fixed build 4.8.09214.01
🔗 References (15)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36042
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.7
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033922
- referencehttps://support.microsoft.com/help/5034272
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033919
- referencehttps://support.microsoft.com/help/5034276
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033918
- referencehttps://support.microsoft.com/help/5034274
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033920
- referencehttps://support.microsoft.com/help/5033920
- referencehttps://support.microsoft.com/help/5034275
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033917
- referencehttps://support.microsoft.com/help/5033917