2023-06-14 02:00:32 +00:00
|
|
|
{
|
|
|
|
"id": "CVE-2023-33126",
|
|
|
|
"sourceIdentifier": "secure@microsoft.com",
|
|
|
|
"published": "2023-06-14T00:15:11.853",
|
2024-12-08 03:06:42 +00:00
|
|
|
"lastModified": "2024-11-21T08:04:56.533",
|
|
|
|
"vulnStatus": "Modified",
|
2024-07-14 02:06:08 +00:00
|
|
|
"cveTags": [],
|
2023-06-14 02:00:32 +00:00
|
|
|
"descriptions": [
|
|
|
|
{
|
|
|
|
"lang": "en",
|
|
|
|
"value": ".NET and Visual Studio Remote Code Execution Vulnerability"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"metrics": {
|
|
|
|
"cvssMetricV31": [
|
|
|
|
{
|
|
|
|
"source": "secure@microsoft.com",
|
2025-01-12 03:03:49 +00:00
|
|
|
"type": "Primary",
|
2023-06-14 02:00:32 +00:00
|
|
|
"cvssData": {
|
|
|
|
"version": "3.1",
|
|
|
|
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
|
2024-12-08 03:06:42 +00:00
|
|
|
"baseScore": 7.3,
|
|
|
|
"baseSeverity": "HIGH",
|
2023-06-14 02:00:32 +00:00
|
|
|
"attackVector": "LOCAL",
|
|
|
|
"attackComplexity": "LOW",
|
|
|
|
"privilegesRequired": "LOW",
|
|
|
|
"userInteraction": "REQUIRED",
|
|
|
|
"scope": "UNCHANGED",
|
|
|
|
"confidentialityImpact": "HIGH",
|
|
|
|
"integrityImpact": "HIGH",
|
2024-12-08 03:06:42 +00:00
|
|
|
"availabilityImpact": "HIGH"
|
2023-06-14 02:00:32 +00:00
|
|
|
},
|
|
|
|
"exploitabilityScore": 1.3,
|
|
|
|
"impactScore": 5.9
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
2023-06-21 20:00:31 +00:00
|
|
|
"weaknesses": [
|
|
|
|
{
|
|
|
|
"source": "nvd@nist.gov",
|
|
|
|
"type": "Primary",
|
|
|
|
"description": [
|
|
|
|
{
|
|
|
|
"lang": "en",
|
|
|
|
"value": "NVD-CWE-noinfo"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"configurations": [
|
|
|
|
{
|
|
|
|
"nodes": [
|
|
|
|
{
|
|
|
|
"operator": "OR",
|
|
|
|
"negate": false,
|
|
|
|
"cpeMatch": [
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "6.0.0",
|
|
|
|
"versionEndExcluding": "6.0.18",
|
|
|
|
"matchCriteriaId": "A00E1F46-D02A-42C8-9292-F38BE98DE1CD"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "7.0.0",
|
|
|
|
"versionEndExcluding": "7.0.7",
|
|
|
|
"matchCriteriaId": "5FABF6D4-EA23-4234-90D3-0D9306A2994B"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "17.0",
|
|
|
|
"versionEndExcluding": "17.0.22",
|
|
|
|
"matchCriteriaId": "2B1F98BC-0D82-4AEB-9E1E-D67325E99385"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "17.2",
|
|
|
|
"versionEndExcluding": "17.2.16",
|
|
|
|
"matchCriteriaId": "B6B0B496-BC41-4F9D-9A28-AE7664B5C77D"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "17.4",
|
|
|
|
"versionEndExcluding": "17.4.8",
|
|
|
|
"matchCriteriaId": "BC861E65-1682-4E99-8A7B-F4A31DDC0198"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "17.6",
|
|
|
|
"versionEndExcluding": "17.6.3",
|
|
|
|
"matchCriteriaId": "51DB90D6-C1C4-43B9-8B37-696CB361F37F"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
],
|
2023-06-14 02:00:32 +00:00
|
|
|
"references": [
|
|
|
|
{
|
|
|
|
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33126",
|
2023-06-21 20:00:31 +00:00
|
|
|
"source": "secure@microsoft.com",
|
|
|
|
"tags": [
|
|
|
|
"Patch",
|
|
|
|
"Vendor Advisory"
|
|
|
|
]
|
2024-12-08 03:06:42 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33126",
|
|
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
|
|
"tags": [
|
|
|
|
"Patch",
|
|
|
|
"Vendor Advisory"
|
|
|
|
]
|
2023-06-14 02:00:32 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|