First published: Fri Nov 01 2024(Updated: )
.NET and Visual Studio Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/System.Formats.Nrbf | <9.0.0 | 9.0.0 |
Microsoft PowerShell 7.5 | ||
Microsoft PowerShell 7.5 | ||
Microsoft PowerShell 7.5 | ||
Microsoft .NET 9.0 | ||
Microsoft .NET 9.0 | ||
Microsoft .NET 9.0 | ||
Visual Studio Community 2022 | =17.10 | |
Visual Studio Community 2022 | =17.6 | |
Visual Studio Community 2022 | =17.8 | |
All of | ||
Microsoft .NET Framework | =9.0.0 | |
Any of | ||
macOS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Visual Studio Community 2022 | >=17.6<17.6.21 | |
Visual Studio Community 2022 | >=17.8<17.8.16 | |
Visual Studio Community 2022 | >=17.10.0<17.10.9 | |
Visual Studio Community 2022 | >=17.11.0<17.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43498 is classified as a Remote Code Execution vulnerability in .NET and Visual Studio.
To fix CVE-2024-43498, you need to update to the latest version of Visual Studio 2022 or .NET 9.0.
CVE-2024-43498 affects Visual Studio 2022 versions 17.6, 17.8, and 17.10.
Yes, .NET 9.0 applications installed on Linux are vulnerable to CVE-2024-43498.
CVE-2024-43498 affects Windows, MacOS, and Linux platforms with vulnerable versions of .NET and Visual Studio.