CVE-2021-34485 vulnerability in Microsoft Products
Published on August 12, 2021
.NET Core and Visual Studio Information Disclosure Vulnerability
.NET Core and Visual Studio Information Disclosure Vulnerability
Products Associated with CVE-2021-34485
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8):- Version 15.9.0 and below 15.9.38 is affected.
- Version 16.0 and below 16.4.25 is affected.
- Version 16.0.0 and below 16.7.18 is affected.
- Version 15.0.0 and below 16.9.10 is affected.
- Version 16.10.0 and below 16.10.5 is affected.
- Version 7.1.0 and below 7.1.4 is affected.
- Version 7.0.0 and below 7.0.7 is affected.
- Version 2.1 and below 2.1.30 is affected.
- Version 3.1 and below 3.1.18 is affected.
- Version 5.0.0 and below 5.0.9 is affected.
Vulnerable Packages
The following package name and versions may be associated with CVE-2021-34485
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| nuget | Microsoft.NETCore.App.Runtime.linux-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.linux-arm | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.osx-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.win-arm | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.win-arm64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.win-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.win-x86 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App | >= 2.1.0, < 2.1.29 | 2.1.29 |
| nuget | Microsoft.NETCore.App.Runtime.linux-arm | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.linux-arm64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.linux-musl-x64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.linux-x64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.osx-x64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.rhel.6-x64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.win-arm | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.win-arm64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.win-x64 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.win-x86 | >= 3.1.0, < 3.1.18 | 3.1.18 |
| nuget | Microsoft.NETCore.App.Runtime.linux-arm | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.linux-arm64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.linux-musl-arm | >= 5.0.0, < 5.0.9 | 5.0.9 |
| nuget | Microsoft.NETCore.App.Runtime.linux-musl-x64 | >= 5.0.0, < 5.0.9 | 5.0.9 |
Exploit Probability
EPSS
0.97%
Percentile
76.36%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.