CVE-2024-43498CriticalCVSS 9.8
.NET and Visual Studio Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? A remote unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to a vulnerable .NET webapp or by loading a specially crafted file into a vulnerable desktop app.
🎯 Affected products10
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- Microsoft Visual Studio 2022 version 17.10
- Microsoft Visual Studio 2022 version 17.11
- Microsoft Visual Studio 2022 version 17.6
- Microsoft Visual Studio 2022 version 17.8
- PowerShell 7.5 installed on Linux
- PowerShell 7.5 installed on MacOS
- PowerShell 7.5 installed on Windows
✅ Remediation
KBRelease Note (Security Update) — fixed build 7.5.0 KBRelease Notes (Security Update) — fixed build 17.8.16 KBRelease Notes (Security Update) — fixed build 17.6.21 KBRelease Notes (Security Update) — fixed build 17.10.9 KBRelease Notes (Security Update) — fixed build 17.11.6 KBRelease Notes (Security Update) — fixed build 9.0.0
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43498
- patchhttps://github.com/PowerShell/Announcements/issues/74
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.11
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/9.0
- referencehttps://github.com/dotnet/announcements/issues/334