.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-38229

8.1HIGH

Summary

This vulnerability in .NET and Visual Studio could allow an attacker to execute arbitrary code on a system if a user opens a specially crafted project file or accesses a malicious web page. This risk emphasizes the importance of maintaining up-to-date security practices and patches to safeguard development environments from potential exploits.

Affected Version(s)

.NET 8.0 Unknown 8.0.0 < 8.0.10

Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.8

Microsoft Visual Studio 2022 version 17.11 Unknown 17.11 < 17.11.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.