CVE-2023-33144
Es existieren mehrere Schwachstellen in verschiedenen Microsoft Developer Tools. Die Fehler bestehen u.a. durch mehrere Pufferüberläufe, unsachgemäße Eingabeüberprüfungen und unzureichende Überprüfungen. Die meisten der Schwachstellen sind noch nicht im Detail beschrieben. Zu den betroffenen Komponenten gehören unter anderem AutoDesk und GitHub für Microsoft Visual Studio. Ein Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Rechte zu erweitern und Daten zu manipulieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.72% · 72.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft .NET Framework 4.6.2 | |
| Microsoft | Microsoft NuGet 6.4.1 | |
| Microsoft | Microsoft Visual Studio 2015 Update 3 | |
| Microsoft | Microsoft .NET Framework 4.8.1 | |
| Microsoft | Microsoft .NET Framework 4.7.2 | |
| Oracle | Oracle Linux | |
| Microsoft | Microsoft .NET Framework 2.0 SP2 | |
| Red Hat | Red Hat Enterprise Linux | |
| Microsoft | Microsoft NuGet 6.2.3 | |
| Microsoft | Microsoft .NET Framework 3.0 SP2 | |
| Microsoft | Microsoft Visual Studio 2022 version 17.2 | |
| Microsoft | Microsoft Visual Studio Code | |
| Microsoft | Microsoft Visual Studio 2022 version 17.4 | |
| Microsoft | Microsoft Azure DevOps Server 2020.1.2 | |
| Microsoft | Microsoft .NET Framework 4.7.1 | |
| Microsoft | Microsoft .NET Framework 3.5 | |
| Microsoft | Microsoft NuGet 6.0.4 | |
| Hitachi | Hitachi Storage Virtual Storage Platform | |
| Microsoft | Microsoft .NET Framework 3.5.1 | |
| Microsoft | Microsoft Visual Studio 2019 version 16.11 |
…and 11 more
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (circl)
- CVE-2023-4863.yar (github-yara)
- CVE-2023-4863.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- CVE-2023-4863.yar (github-yara)
…and 14 more exploits
Timeline
- Jun 13, 2023 CVE Published
- Jun 14, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
- Sep 29, 2023 EPSS Score
- Oct 5, 2023 PoC Published
- Nov 3, 2023 EPSS Score
- Jan 13, 2024 EPSS Score
- Feb 18, 2024 EPSS Score
- Mar 24, 2024 EPSS Score
- Jun 3, 2024 EPSS Score
- Jul 10, 2024 EPSS Score
- Aug 14, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1446.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1446 advisory
- https://www.hitachi.com/products/it/storage-solutions/sec_info/2023/06.html advisory
- https://access.redhat.com/errata/RHSA-2023:4449 advisory
- https://access.redhat.com/errata/RHSA-2023:4448 advisory
- https://ubuntu.com/security/notices/USN-6161-2 advisory
- https://linux.oracle.com/errata/ELSA-2023-3592.html advisory
- https://linux.oracle.com/errata/ELSA-2023-3593.html advisory
- https://linux.oracle.com/errata/ELSA-2023-3582.html advisory
- http://linux.oracle.com/errata/ELSA-2023-3581.html advisory
- https://access.redhat.com/errata/RHSA-2023:3593 advisory
- https://access.redhat.com/errata/RHSA-2023:3581 advisory
- https://access.redhat.com/errata/RHSA-2023:3580 advisory
- https://access.redhat.com/errata/RHSA-2023:3582 advisory
- https://access.redhat.com/errata/RHSA-2023:3592 advisory
- https://ubuntu.com/security/notices/USN-6161-1 advisory
- https://msrc.microsoft.com/update-guide advisory