CVE-2023-35390
.NET and Visual Studio Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
.NET and Visual Studio Remote Code Execution Vulnerability
Vulnerabilidad de ejecución remota de código de .NET y Visual Studio
A vulnerability was found in dotnet. This issue exists when some dotnet commands are used in directories with weaker permissions, which can result in remote code execution.
It was discovered that .NET did not properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. Benoit Foucher discovered that .NET did not properly implement the QUIC stream limit in HTTP/3. An attacker could possibly use this issue to cause a denial of service. It was discovered that .NET did not properly handle the disconnection of potentially malicious clients interfacing with a Kestrel server. An attacker could possibly use this issue to cause a denial of service.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-06-14 CVE Reserved
- 2023-08-08 CVE Published
- 2025-01-01 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35390 | 2024-05-29 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-35390 | 2023-08-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2228622 | 2023-08-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | .net Search vendor "Microsoft" for product ".net" | >= 6.0.0 < 6.0.21 Search vendor "Microsoft" for product ".net" and version " >= 6.0.0 < 6.0.21" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Search vendor "Microsoft" for product ".net" | >= 7.0.0 < 7.0.10 Search vendor "Microsoft" for product ".net" and version " >= 7.0.0 < 7.0.10" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio 2022 Search vendor "Microsoft" for product "Visual Studio 2022" | >= 17.2.0 < 17.2.18 Search vendor "Microsoft" for product "Visual Studio 2022" and version " >= 17.2.0 < 17.2.18" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio 2022 Search vendor "Microsoft" for product "Visual Studio 2022" | >= 17.4.0 < 17.4.10 Search vendor "Microsoft" for product "Visual Studio 2022" and version " >= 17.4.0 < 17.4.10" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio 2022 Search vendor "Microsoft" for product "Visual Studio 2022" | >= 17.6.0 < 17.6.6 Search vendor "Microsoft" for product "Visual Studio 2022" and version " >= 17.6.0 < 17.6.6" | - |
Affected
|