CVE-2024-43499HighCVSS 7.5
.NET and Visual Studio Denial of Service Vulnerability
🔗 CVE IDs covered (1)
🎯 Affected products10
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- Microsoft Visual Studio 2022 version 17.10
- Microsoft Visual Studio 2022 version 17.11
- Microsoft Visual Studio 2022 version 17.6
- Microsoft Visual Studio 2022 version 17.8
- PowerShell 7.5 installed on Linux
- PowerShell 7.5 installed on MacOS
- PowerShell 7.5 installed on Windows
✅ Remediation
KBRelease Notes (Security Update) — fixed build 17.6.21 KBRelease Notes (Security Update) — fixed build 17.10.9 KBRelease Notes (Security Update) — fixed build 17.8.16 KBRelease Notes (Security Update) — fixed build 17.11.6 KBReleae Notes (Security Update) — fixed build 7.5.0 KBRelease Notes (Security Update) — fixed build 9.0.0
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43499
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.11
- patchhttps://github.com/PowerShell/Announcements/issues/73
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/9.0
- referencehttps://github.com/dotnet/announcements/issues/333