.NET/VS Elevation of Privilege via Internal Buffer Overflow
CVE-2023-33127 Published on July 11, 2023
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
Weakness Type
Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Products Associated with CVE-2023-33127
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-33127 are published in these products:
Affected Versions
Microsoft .NET 6.0:- Version 6.0.0 and below 6.0.20 is affected.
- Version 7.0.0 and below 7.0.9 is affected.
- Version 17.0.0 and below 17.0.23 is affected.
- Version 17.2.0 and below 17.2.17 is affected.
- Version 17.4.0 and below 17.4.9 is affected.
- Version 17.6.0 and below 17.6.5 is affected.
- Version 7.2.0 and below 7.2.13 is affected.
- Version 7.3.0 and below 7.3.6 is affected.
Vulnerable Packages
The following package name and versions may be associated with CVE-2023-33127
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| nuget | Microsoft.WindowsDesktop.App.Runtime.win-arm64 | >= 7.0.0, < 7.0.9 | 7.0.9 |
| nuget | Microsoft.WindowsDesktop.App.Runtime.win-arm64 | >= 6.0.0, < 6.0.20 | 6.0.20 |
| nuget | Microsoft.WindowsDesktop.App.Runtime.win-x64 | >= 7.0.0, < 7.0.9 | 7.0.9 |
| nuget | Microsoft.WindowsDesktop.App.Runtime.win-x64 | >= 6.0.0, < 6.0.20 | 6.0.20 |
| nuget | Microsoft.WindowsDesktop.App.Runtime.win-x86 | >= 6.0.0, < 6.0.20 | 6.0.20 |
| nuget | Microsoft.WindowsDesktop.App.Runtime.win-x86 | >= 7.0.0, < 7.0.9 | 7.0.9 |
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.