CVE-2024-38229HighCVSS 8.1

.NET and Visual Studio Remote Code Execution Vulnerability

Published
October 8, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition.

🎯 Affected products7

  • .NET 8.0 installed on Linux
  • .NET 8.0 installed on Mac OS
  • .NET 8.0 installed on Windows
  • Microsoft Visual Studio 2022 version 17.10
  • Microsoft Visual Studio 2022 version 17.11
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.8

✅ Remediation

KBRelease Notes (Security Update) — fixed build 17.6.20 KBRelease Notes (Security Update) — fixed build 17.8.15 KBRelease Notes (Security Update) — fixed build 17.10.8 KB5045993 (Security Update) — fixed build 8.0.10 KBRelease Notes (Security Update) — fixed build 17.11.5

🔗 References (8)