CVE-2023-36799HighCVSS 6.5

.NET Core and Visual Studio Denial of Service Vulnerability

Published
September 12, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker must send the user a malicious request and convince them to open it.

🎯 Affected products8

  • .NET 6.0
  • .NET 7.0
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.7
  • PowerShell 7.2
  • PowerShell 7.3

✅ Remediation

KB5032874 (Security Update) — fixed build 6.0.24 KB5032875 (Security Update) — fixed build 7.0.13 KBRelease Notes (Security Update) — fixed build 17.2.21 KBRelease Notes (Security Update) — fixed build 17.4.13 KBRelease Notes (Security Update) — fixed build 17.6.9 KBRelease Notes (Security Update) — fixed build 7.2.14

🔗 References (11)