CVE-2023-36899: ASP.NET Elevation of Privilege Vulnerability
ASP.NET Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20107Patch KB5029259 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6167Patch KB5029242 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8974Fixed in 3.0.50727.8974Patch KB5029569 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04057.05Fixed in 4.7.4057.04Patch KB5029569 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04057.05Fixed in 4.7.04057.04Patch KB5029569 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.09176.01Patch KB5029655 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04057.07Fixed in 4.7.04057.06Patch KB5029568 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09176.01Patch KB5029649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.04057.05Patch KB5029647 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4057.05Patch KB5029647 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.08Patch KB5029647 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.06Patch KB5029650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.06Patch KB5029655 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.06Patch KB5028952 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.4654.08Patch KB5029647 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4654.06Patch KB5028952 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09176.01Patch KB5029648 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09176.01Patch KB5028948 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09176.01Patch KB5029650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04057.05Fixed in 4.7.04057.04Patch KB5029567 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04057.05Fixed in 4.7.4057.04Patch KB5029566 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.06Patch KB5029649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.06Patch KB5029648 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.08Fixed in 4.8.04654.07Patch KB5029568 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04654.06Fixed in 4.8.04654.05Patch KB5029567 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4654.06Fixed in 4.8.04654.05Patch KB5029566
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36899?
CVE-2023-36899 is classified as an elevation of privilege vulnerability in Microsoft .NET Framework.
How do I fix CVE-2023-36899?
To fix CVE-2023-36899, apply the security updates released by Microsoft for the affected versions of the .NET Framework.
What versions of .NET Framework are affected by CVE-2023-36899?
CVE-2023-36899 affects .NET Framework versions 2.0, 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, and 4.8.
Can CVE-2023-36899 be exploited remotely?
CVE-2023-36899 can potentially be exploited remotely, allowing attackers to elevate privileges.
Is CVE-2023-36899 present in recent Windows versions?
CVE-2023-36899 does not affect the latest Windows Server and Windows 10/11 releases if they have the latest security updates installed.