First published: Wed Aug 02 2023(Updated: )
.NET and Visual Studio Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.NET.Build.Containers | <=7.0.306 | 7.0.307 |
Microsoft .NET 7.0 | ||
Microsoft .NET 6.0 | ||
Microsoft Visual Studio 2022 | =17.2 | |
Microsoft Visual Studio 2022 | =17.4 | |
Microsoft .NET | >=6.0.0<6.0.21 | |
Microsoft .NET | >=7.0.0<7.0.10 | |
Microsoft Visual Studio 2022 | >=17.2.0<17.2.18 | |
Microsoft Visual Studio 2022 | >=17.4.0<17.4.10 | |
Microsoft Visual Studio 2022 | >=17.6.0<17.6.6 | |
redhat/.NET SDK | <6.0.121 | 6.0.121 |
redhat/.NET SDK | <7.0.110 | 7.0.110 |
redhat/.NET Runtime | <6.0.21 | 6.0.21 |
redhat/.NET Runtime | <7.0.10 | 7.0.10 |
ubuntu/dotnet6 | <6.0.121-0ubuntu1~23.04.1 | 6.0.121-0ubuntu1~23.04.1 |
ubuntu/dotnet6 | <6.0.21 | 6.0.21 |
ubuntu/dotnet6 | <6.0.121-0ubuntu1~22.04.1 | 6.0.121-0ubuntu1~22.04.1 |
ubuntu/dotnet7 | <7.0.110-0ubuntu1~23.04.1 | 7.0.110-0ubuntu1~23.04.1 |
ubuntu/dotnet7 | <7.0.10 | 7.0.10 |
ubuntu/dotnet7 | <7.0.110-0ubuntu1~22.04.1 | 7.0.110-0ubuntu1~22.04.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35390 is a .NET and Visual Studio Remote Code Execution Vulnerability.
CVE-2023-35390 has a severity value of 7.8, which is considered high.
CVE-2023-35390 affects Microsoft Visual Studio 2022 versions 17.2 to 17.4, .NET 6.0 versions 6.0.0 to 6.0.21, and .NET 7.0 versions 7.0.0 to 7.0.10.
To fix the CVE-2023-35390 vulnerability in Visual Studio 2022, you should update to version 17.4 or higher by downloading the patch from the Visual Studio website.
To fix the CVE-2023-35390 vulnerability in .NET 6.0 and 7.0, you should update to the latest version by downloading the patch from the official Microsoft website.