Lucene search

K
kasperskyKaspersky LabKLA12474
HistoryMar 08, 2022 - 12:00 a.m.

KLA12474 Multiple vulnerabilities in Microsoft Developer Tools

2022-03-0800:00:00
Kaspersky Lab
threats.kaspersky.com
108

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

8.8 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.0%

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to spoof user interface, execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A spoofing vulnerability in Visual Studio Code can be exploited remotely to spoof user interface.
  2. A remote code execution vulnerability in .NET and Visual Studio can be exploited remotely to execute arbitrary code.
  3. A denial of service vulnerability in .NET and Visual Studio can be exploited remotely to cause denial of service.
  4. Buffer overflow vulnerability in Brotli library can be exploited to cause denial of service.

Original advisories

CVE-2022-24526

CVE-2022-24512

CVE-2022-24464

CVE-2020-8927

Related products

Microsoft-Visual-Studio

CVE list

CVE-2022-24526 high

CVE-2022-24512 high

CVE-2022-24464 critical

CVE-2020-8927 high

KB list

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6).NET 6.0.NET Core 3.1Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)Microsoft Visual Studio 2022 version 17.0Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10).NET 5.0

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

8.8 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.0%