KLA12073
Multiple vulnerabilities in Microsoft Developer Tools

Updated: 02/16/2021
Detect date
?
02/09/2021
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in .NET Core can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in Visual Studio Code can be exploited remotely to execute arbitrary code.
  3. An elevation of privilege vulnerability in Sysinternals PsExec can be exploited remotely to gain privileges.
  4. A denial of service vulnerability in .NET Core and Visual Studio can be exploited remotely to cause denial of service.
  5. A remote code execution vulnerability in Package Managers Configurations can be exploited remotely to execute arbitrary code.
  6. A remote code execution vulnerability in Visual Studio Code npm-script Extension can be exploited remotely to execute arbitrary code.
  7. A denial of service vulnerability in .NET Framework can be exploited remotely to cause denial of service.
Affected products

.NET Core 2.1
Microsoft Visual Studio 2019 version 16.8
Visual Studio Code
Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
Microsoft .NET Framework 4.7.2
.NET Core 3.1
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
Visual Studio Code - npm-script Extension
Microsoft .NET Framework 4.6
.NET 5.0
PsExec
Package Manager Configurations
Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2
Microsoft .NET Framework 4.8
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-26701
CVE-2021-1639
CVE-2021-1733
CVE-2021-1721
CVE-2021-24105
CVE-2021-26700
CVE-2021-24111
CVE-2021-24112

Impacts
?
ACE 
[?]

DoS 
[?]

PE 
[?]
Related products
Microsoft .NET Framework
Microsoft Visual Studio
Microsoft PsExec
CVE-IDS
?
CVE-2021-267017.5Critical
CVE-2021-16396.8High
CVE-2021-17334.6Warning
CVE-2021-17214.3Warning
CVE-2021-241056.8High
CVE-2021-267006.8High
CVE-2021-241115.0Critical
CVE-2021-241127.5Critical
KB list

4601354
4601318
4602960
4601056
4603002
4601050
4603004
4602961
4602959
4603003
4601051
4601887
4601054
4602958
4603005

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region