CVE-2024-21392HighCVSS 7.5
.NET and Visual Studio Denial of Service Vulnerability
🔗 CVE IDs covered (1)
🎯 Affected products8
- .NET 7.0
- .NET 8.0
- Microsoft Visual Studio 2022 version 17.4
- Microsoft Visual Studio 2022 version 17.6
- Microsoft Visual Studio 2022 version 17.8
- Microsoft Visual Studio 2022 version 17.9
- PowerShell 7.3
- PowerShell 7.4
✅ Remediation
KBRelease Notes (Security Update) — fixed build 17.9.3 KBRelease Notes (Security Update) — fixed build 7.3.12 KBRelease Notes (Security Update) — fixed build 7.4.1 KB5036451 (Monthly Rollup) — fixed build 7.0.17 KB5036452 (Security Update) — fixed build 8.0.3 KBRelease Notes (Security Update) — fixed build 17.6.13 KBRelease Notes (Security Update) — fixed build 17.4.17 KBRelease Notes (Security Update) — fixed build 17.8.8
🔗 References (11)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21392
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.9
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://github.com/PowerShell/Announcements/issues/59
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/7.0
- referencehttps://support.microsoft.com/help/5036451
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/8.0
- referencehttps://support.microsoft.com/help/5036452
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.4
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8