GHSA-mqvm-gmc4-6rv2: Buffer Overflow
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-527h-q9f6-p7qx. This link is maintained to preserve external references.
Original Description Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.DiaSymReader.Nativeto a version that resolves this vulnerability.Fixed in 18.9.0-beta1.26405.2
Event History
Frequently Asked Questions
Should this advisory be tracked as an independent issue?
No. It was withdrawn as a duplicate of GHSA-527h-q9f6-p7qx and is retained only to preserve external references. Track the duplicate advisory for authoritative remediation and affected-version information.
What is known about exploitation prerequisites from this record?
The supplied severity vector indicates network attack reachability, low attack complexity, no required privileges, and required user interaction. The record does not state what user action is required or provide affected-version details.