Lucene search

K
kasperskyKaspersky LabKLA12245
HistoryJul 13, 2021 - 12:00 a.m.

KLA12245 Multiple vulnerabilities in Microsoft Developer Tools

2021-07-1300:00:00
Kaspersky Lab
threats.kaspersky.com
17
microsoft developer tools
remote code execution
arbitrary code execution
elevation of privilege
spoofing
visual studio code
.net runtime
open enclave sdk
cve-2021-34529
cve-2021-34477
cve-2021-34479
cve-2021-34528
cve-2021-33767
windows update
arbitrary code execution
privilege escalation
spoof user interface
affected products

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.079

Percentile

94.4%

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Visual Studio Code can be exploited remotely to execute arbitrary code.
  2. An elevation of privilege vulnerability in Visual Studio Code .NET Runtime can be exploited remotely to gain privilege.
  3. A spoofing vulnerability in Microsoft Visual Studio can be exploited remotely to spoof user interface.
  4. An elevation of privilege vulnerability in Open Enclave SDK can be exploited remotely to gain privilege.

Original advisories

CVE-2021-34529

CVE-2021-34477

CVE-2021-34479

CVE-2021-34528

CVE-2021-33767

Related products

Microsoft-Visual-Studio

CVE list

CVE-2021-34529 unknown

CVE-2021-34477 unknown

CVE-2021-34479 unknown

CVE-2021-34528 unknown

CVE-2021-33767 unknown

KB list

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Microsoft Visual StudioVisual Studio Code .NET RuntimeVisual Studio CodeOpen Enclave SDK

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.079

Percentile

94.4%