KLA20123
Multiple vulnerabilities in Microsoft Developer Tools

Обновлено: 16/05/2023
Дата обнаружения
13/12/2022
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in Microsoft Windows Sysmon can be exploited remotely to gain privileges.
  2. A remote code execution vulnerability in PowerShell can be exploited remotely to execute arbitrary code.
  3. A remote code execution vulnerability in .NET Framework can be exploited remotely to execute arbitrary code.
Эксплуатация

The following public exploits exists for this vulnerability:

https://github.com/5l1v3r1/CVE-2022-41076

Пораженные продукты

Microsoft .NET Framework 3.5 AND 4.8.1
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
Microsoft .NET Framework 4.8
.NET 7.0
Windows Sysmon
Microsoft .NET Framework 3.5.1
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Microsoft .NET Framework 3.5
Microsoft Visual Studio 2022 version 17.4
.NET 6.0
PowerShell 7.3
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 AND 4.8
Microsoft Visual Studio 2022 version 17.2
PowerShell 7.2
Microsoft Visual Studio 2022 version 17.0
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.5 AND 4.7.2
.NET Core 3.1
Microsoft .NET Framework 3.5 AND 4.6/4.6.2

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2022-44704
CVE-2022-41076
CVE-2022-41089
Оказываемое влияние
?
ACE 
[?]

PE 
[?]
Связанные продукты
Microsoft .NET Framework
Microsoft Visual Studio
Microsoft Windows
CVE-IDS
CVE-2022-410765.0Critical
CVE-2022-447045.0Critical
CVE-2022-410895.0Critical
KB list

5021243
5021953
5020880
5021082
5021094
5021093
5021954
5021085
5021092
5021086
5020873
5021080
5020868
5021088
5021095
5021081
5021079
5021091
5021955
5021089
5021090
5021087