.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-35264
8.1HIGH
Summary
A vulnerability in .NET and Visual Studio allows for remote code execution, presenting risks for developers and systems using these platforms. Attackers may exploit this flaw to execute arbitrary code in the context of the user running the vulnerable application. This could lead to unauthorized actions taken on behalf of the user. It is crucial for organizations to address this vulnerability by applying available patches and implementing best practices for secure coding and application deployment.
Affected Version(s)
.NET 6.0 Unknown
.NET 8.0 Unknown 1.0.0 < 8.0.7
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.4
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed