Elevation of Privilege Vulnerability Affects Microsoft Products

CVE-2023-36049
9.8CRITICAL

Key Information

Vendor
Microsoft
Status
Microsoft Visual Studio 2022 Version 17.2
Microsoft Visual Studio 2022 Version 17.4
Microsoft Visual Studio 2022 Version 17.7
Microsoft Visual Studio 2022 Version 17.6
Vendor
CVE Published:
14 November 2023

Badges

👾 Exploit Exists📰 News Worthy

Summary

A vulnerability with high CVSS scores has been identified in the .NET Framework, allowing for the elevation of privilege and security feature bypass. This vulnerability specifically affects FTP operations and allows unauthorized users to write or delete files on the server, potentially leading to data loss, data corruption, or unauthorized access to sensitive information. Microsoft has released patches to address the flaws, and users are urged to apply the updates promptly in order to safeguard against potential attacks. The exploitation of these vulnerabilities could have a significant impact on affected systems, especially those relying on the .NET Framework for FTP operations.

Affected Version(s)

Microsoft Visual Studio 2022 version 17.2 < 17.2.22

Microsoft Visual Studio 2022 version 17.4 < 17.4.14

Microsoft Visual Studio 2022 version 17.7 < 17.7.7

News Articles

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Risk change from: 9.8 to: 7.6 - (HIGH)

  • First article discovered by Zero Day Initiative

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed3 News Article(s)
.