CVE-2024-38167HighCVSS 6.5
.NET and Visual Studio Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? An attacker who successfully exploited the vulnerability could read targeted email messages.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of this vulnerability requires that a user trigger the payload in the application.
🎯 Affected products4
- .NET 8.0
- Microsoft Visual Studio 2022 version 17.10
- Microsoft Visual Studio 2022 version 17.6
- Microsoft Visual Studio 2022 version 17.8
✅ Remediation
KBRelease Notes (Security Update) — fixed build 17.10.6 KBRelease Notes (Security Update) — fixed build 17.8.13 KB5042132 (Security Update) — fixed build 8.0.8 KBRelease Notes (Security Update) — fixed build 17.6.18
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38167
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/8.0
- referencehttps://support.microsoft.com/help/5042132
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6