.NET Framework & VS Remote Code Execution Vulnerability
CVE-2023-24897 Published on June 14, 2023

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Github Repository Vendor Advisory NVD

Weakness Type

Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().


Products Associated with CVE-2023-24897

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 

Affected Versions

Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8): Microsoft Visual Studio 2022 version 17.2: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10): Microsoft Visual Studio 2022 version 17.0: Microsoft Visual Studio 2022 version 17.4: Microsoft Visual Studio 2013 Update 5: Microsoft Visual Studio 2015 Update 3: Microsoft .NET 7.0: Microsoft .NET 6.0: Microsoft Visual Studio 2022 version 17.6: Microsoft PowerShell 7.2: Microsoft .NET Framework 3.5 AND 4.8: Microsoft .NET Framework 4.8: Microsoft .NET Framework 3.5 AND 4.7.2: Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2: Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2: Microsoft .NET Framework 3.5 AND 4.8.1: Microsoft .NET Framework 4.6.2: Microsoft .NET Framework 3.5 and 4.6.2:

Vulnerable Packages

The following package name and versions may be associated with CVE-2023-24897

Package Manager Vulnerable Package Versions Fixed In
nuget Microsoft.NetCore.App.Runtime.win-arm64 >= 6.0.0, <= 6.0.16 6.0.18
nuget Microsoft.NetCore.App.Runtime.win-x86 >= 6.0.0, <= 6.0.16 6.0.18
nuget Microsoft.NetCore.App.Runtime.win-x64 >= 6.0.0, <= 6.0.16 6.0.18
nuget Microsoft.NetCore.App.Runtime.win-arm >= 6.0.0, <= 6.0.16 6.0.18
nuget Microsoft.NetCore.App.Runtime.win-x86 >= 7.0.0, <= 7.0.5 7.0.7
nuget Microsoft.NetCore.App.Runtime.win-x64 >= 7.0.0, <= 7.0.5 7.0.7
nuget Microsoft.NetCore.App.Runtime.win-arm64 >= 7.0.0, <= 7.0.5 7.0.7
nuget Microsoft.NetCore.App.Runtime.win-arm >= 7.0.0, <= 7.0.5 7.0.7

Exploit Probability

EPSS
1.90%
Percentile
83.03%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.