First published: Tue Jun 06 2023(Updated: )
.NET and Visual Studio Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-dotnet60-dotnet | <0:6.0.118-1.el7_9 | 0:6.0.118-1.el7_9 |
redhat/dotnet6.0 | <0:6.0.118-1.el8_8 | 0:6.0.118-1.el8_8 |
redhat/dotnet7.0 | <0:7.0.107-1.el8_8 | 0:7.0.107-1.el8_8 |
redhat/dotnet6.0 | <0:6.0.120-1.el8_6 | 0:6.0.120-1.el8_6 |
redhat/dotnet6.0 | <0:6.0.118-1.el9_2 | 0:6.0.118-1.el9_2 |
redhat/dotnet7.0 | <0:7.0.107-1.el9_2 | 0:7.0.107-1.el9_2 |
redhat/dotnet6.0 | <0:6.0.120-1.el9_0 | 0:6.0.120-1.el9_0 |
nuget/Microsoft.NetCore.App.Runtime.win-x86 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.win-x64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.win-arm64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.win-arm | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.osx-x64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.osx-arm64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.linux-x64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.linux-musl-x64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.linux-arm64 | >=7.0.0<=7.0.5 | 7.0.7 |
nuget/Microsoft.NetCore.App.Runtime.linux-arm | >=7.0.0<=7.0.5 | 7.0.7 |
Microsoft .NET | >=6.0.0<6.0.18 | |
Microsoft .NET | >=7.0.0<7.0.7 | |
Microsoft Visual Studio 2022 | >=17.0<17.0.22 | |
Microsoft Visual Studio 2022 | >=17.2<17.2.16 | |
Microsoft Visual Studio 2022 | >=17.4<17.4.8 | |
Microsoft Visual Studio 2022 | >=17.6<17.6.3 | |
Microsoft PowerShell 7.3 | ||
Microsoft Visual Studio 2022 | =17.4 | |
Microsoft .NET 6.0 | ||
Microsoft .NET 7.0 | ||
Microsoft Visual Studio 2022 | =17.0 | |
Microsoft Visual Studio 2022 | =17.2 | |
>=6.0.0<6.0.18 | ||
>=7.0.0<7.0.7 | ||
>=17.0<17.0.22 | ||
>=17.2<17.2.16 | ||
>=17.4<17.4.8 | ||
>=17.6<17.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2023-33128 is high.
CVE-2023-33128 affects Microsoft PowerShell 7.3 and requires a patch for remediation.
The remedy for CVE-2023-33128 in Visual Studio 2022 version 17.2 is to apply the patch provided by Microsoft.
To fix CVE-2023-33128 in .NET 7.0, download and apply the patch provided by Microsoft.
You can find more information about CVE-2023-33128 on the Microsoft Security Response Center website.