Visual Studio Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of this vulnerability requires that an attacker convinces a user to open a maliciously crafted package file in Visual Studio.
🎯 Affected products76
- .NET 6.0
- .NET 7.0
- Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
- Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
- Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
- Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for ARM64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for x64-based Systems
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022
- Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)
- Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems
- +46 more not shown
✅ Remediation
KBRelease Notes (Security Update) — fixed build 15.9.57 KBRelease Notes (Security Update) — fixed build 17.2.21 KBRelease Notes (Security Update) — fixed build 16.11.30 KBRelease Notes (Security Update) — fixed build 17.4.13 KBRelease Notes (Security Update) — fixed build 7.2.12 KB5032874 (Security Update) — fixed build 6.0.24 KB5032875 (Security Update) — fixed build 7.0.13 KBRelease Notes (Security Update) — fixed build 17.6.9 KB5029924 (Security Update) — fixed build 4.8.04667.02 KB5030184 (Monthly Rollup) — fixed build 4.8.04667.02 KB5030183 (Monthly Rollup) — fixed build 4.8.04667.02 KB5030182 (Monthly Rollup) — fixed build 4.8.04667.02 KB5030181 (Security Update) — fixed build 4.8.04667.02 KB5030179 (Security Update) — fixed build 4.8.04667.02 KB5030180 (Security Update) — fixed build 4.8.04667.02 KB5030178 (Security Update) — fixed build 4.7.04063.05 KB5030178 (Security Update) — fixed build 4.8.04667.03 KB5030213 (Security Update) — fixed build 10.0.14393.6252 KB5030182 (Monthly Rollup) — fixed build 4.7.04063.01 KB5030183 (Monthly Rollup) — fixed build 4.7.04063.02 KB5030184 (Monthly Rollup) — fixed build 4.7.04063.02 KB5030186 (Security Update) — fixed build 4.8.09186.01 KB5030181 (Security Update) — fixed build 4.8.09186.01 KB5030179 (Security Update) — fixed build 4.8.09186.01 KB5031217 (Security Update) — fixed build 4.8.09186.0 KB5030180 (Security Update) — fixed build 4.8.09186.01 KB5030185 (Monthly Rollup) — fixed build 4.7.04063.01 KB5030220 (Security Update) — fixed build 10.0.10240.20162 KB5030185 (Monthly Rollup) — fixed build 3.0.30729.8957 KB5030183 (Monthly Rollup) — fixed build 3.0.30729.8957 KB5030184 (Monthly Rollup) — fixed build 3.0.30729.8957 KB5030182 (Monthly Rollup) — fixed build 3.0.30729.8957 KB5030186 (Security Update) — fixed build 4.8.04667.03
🔗 References (50)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36794
- patchhttp://aka.ms/vs/15/release/latest
- referencehttps://docs.microsoft.com/en-us/visualstudio/releasenotes/vs2017-relnotes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.2
- referencehttps://docs.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.11
- referencehttps://docs.microsoft.com/en-us/visualstudio/releases/2019/release-notes-v16.11
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.4
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://github.com/PowerShell/Announcements/issues/50
- patchhttps://dotnet.microsoft.com/download/dotnet/6.0
- referencehttps://support.microsoft.com/help/5032874
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/7.0
- referencehttps://support.microsoft.com/help/5032875
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029924
- referencehttps://support.microsoft.com/help/5029924
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029917
- referencehttps://support.microsoft.com/help/5030184
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029927
- referencehttps://support.microsoft.com/help/5030183
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029929
- referencehttps://support.microsoft.com/help/5030182
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029926
- referencehttps://support.microsoft.com/help/5030181
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029923
- referencehttps://support.microsoft.com/help/5030179
- referencehttps://support.microsoft.com/help/5030180
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029931
- referencehttps://support.microsoft.com/help/5030178
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029925
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5030213
- referencehttps://support.microsoft.com/help/5030213
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029933
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029932
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029916
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029922
- referencehttps://support.microsoft.com/help/5030186
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029920
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029919
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029921
- referencehttps://support.microsoft.com/help/5031217
- referencehttps://support.microsoft.com/help/5030185
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5030220
- referencehttps://support.microsoft.com/help/5030220
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029937
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5030160
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029915
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029938
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5029928