Searching
..

Click anywhere to stop

KLA50771
Multiple vulnerabilities in Microsoft Developer Tools

Обновлено: 25/01/2024
Дата обнаружения
11/07/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, bypass security restrictions, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in MediaWiki PandocUpload Extension can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in Visual Studio Code GitHub Pull Requests and Issues Extension can be exploited remotely to execute arbitrary code.
  3. A spoofing vulnerability in Mono Authenticode Validation can be exploited remotely to spoof user interface.
  4. A security feature bypass vulnerability in ASP.NET and Visual Studio can be exploited remotely to bypass security restrictions.
  5. An elevation of privilege vulnerability in .NET and Visual Studio can be exploited remotely to gain privileges.
Пораженные продукты

PandocUpload
Visual Studio Code - GitHub Pull Requests and Issues Extension
Mono 6.12.0
Microsoft Visual Studio 2022 version 17.4
.NET 6.0
Microsoft Visual Studio 2022 version 17.2
Microsoft Visual Studio 2022 version 17.0
Microsoft Visual Studio 2022 version 17.6
.NET 7.0

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2023-35333
CVE-2023-36867
CVE-2023-35373
CVE-2023-33170
CVE-2023-33127
Оказываемое влияние
?
ACE 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Visual Studio
.NET
CVE-IDS
CVE-2023-331278.1Critical
CVE-2023-331708.1Critical
CVE-2023-353337.5Critical
CVE-2023-368677.8Critical
CVE-2023-353735.3High
KB list

5028705
5028706