CVE-2024-43498CriticalCVSS 9.8

.NET and Visual Studio Remote Code Execution Vulnerability

Published
November 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? A remote unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to a vulnerable .NET webapp or by loading a specially crafted file into a vulnerable desktop app.

🎯 Affected products10

  • .NET 9.0 installed on Linux
  • .NET 9.0 installed on Mac OS
  • .NET 9.0 installed on Windows
  • Microsoft Visual Studio 2022 version 17.10
  • Microsoft Visual Studio 2022 version 17.11
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.8
  • PowerShell 7.5 installed on Linux
  • PowerShell 7.5 installed on MacOS
  • PowerShell 7.5 installed on Windows

✅ Remediation

KBRelease Note (Security Update) — fixed build 7.5.0 KBRelease Notes (Security Update) — fixed build 17.8.16 KBRelease Notes (Security Update) — fixed build 17.6.21 KBRelease Notes (Security Update) — fixed build 17.10.9 KBRelease Notes (Security Update) — fixed build 17.11.6 KBRelease Notes (Security Update) — fixed build 9.0.0

🔗 References (9)