First published: Tue Aug 13 2024(Updated: )
.NET and Visual Studio Information Disclosure Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET 8.0 | ||
nuget/Microsoft.NetCore.App.Runtime.win-x86 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.win-x64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.win-arm64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.win-arm | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.osx-x64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.osx-arm64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.linux-x64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.linux-musl-x64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.linux-arm64 | >=8.0.0<8.0.8 | 8.0.8 |
nuget/Microsoft.NetCore.App.Runtime.linux-arm | >=8.0.0<8.0.8 | 8.0.8 |
Visual Studio Professional 2022 | =17.10 | |
Visual Studio Professional 2022 | =17.6 | |
Visual Studio Professional 2022 | =17.8 | |
Microsoft .NET Framework | >=8.0.0<8.0.8 | |
Visual Studio Professional 2022 | >=17.6.0<17.6.18 | |
Visual Studio Professional 2022 | >=17.8.0<17.8.13 | |
Visual Studio Professional 2022 | >=17.10.0<17.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38167 is categorized as an information disclosure vulnerability that could potentially expose sensitive information.
To mitigate CVE-2024-38167, users should update to the latest versions of Visual Studio 2022 or .NET 8.0 as specified in the advisory.
CVE-2024-38167 affects specific versions of Microsoft Visual Studio 2022 (17.6, 17.8, and 17.10) and .NET 8.0 prior to 8.0.8.
The components involved in CVE-2024-38167 include Visual Studio 2022 and .NET 8.0 runtime packages.
CVE-2024-38167 does not appear to be remotely exploitable as it pertains to information disclosure in local environments.