Lucene search

K
kasperskyKaspersky LabKLA65508
HistoryApr 09, 2024 - 12:00 a.m.

KLA65508 Multiple vulnerabilities in Microsoft Developer Tools

2024-04-0900:00:00
Kaspersky Lab
threats.kaspersky.com
35
microsoft developer tools
multiple vulnerabilities
arbitrary code execution
.net framework
visual studio
security updates
windows update

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.001

Percentile

39.1%

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft ODBC Driver for SQL Server can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in .NET, .NET Framework, and Visual Studio can be exploited remotely to execute arbitrary code.

Original advisories

CVE-2024-28933

CVE-2024-28931

CVE-2024-28932

CVE-2024-28936

CVE-2024-28937

CVE-2024-28935

CVE-2024-28938

CVE-2024-28929

CVE-2024-28930

CVE-2024-21409

CVE-2024-28934

Related products

Microsoft-.NET-Framework

Microsoft-Visual-Studio

.NET

CVE list

CVE-2024-28933 high

CVE-2024-28931 high

CVE-2024-28932 high

CVE-2024-28936 high

CVE-2024-28937 high

CVE-2024-28935 high

CVE-2024-28938 high

CVE-2024-28929 high

CVE-2024-28930 high

CVE-2024-21409 high

CVE-2024-28934 high

KB list

5037041

5037034

5037035

5037337

5037037

5037338

5036620

5037127

5036609

5037033

5037128

5037036

5036899

5037039

5037336

5037040

5037038

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2Microsoft .NET Framework 3.5 AND 4.8Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Microsoft .NET Framework 3.5 AND 4.8.1.NET 7.0Microsoft Visual Studio 2022 version 17.6.NET 6.0Microsoft Visual Studio 2022 version 17.9Microsoft .NET Framework 3.5 AND 4.7.2.NET 8.0Microsoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.8Microsoft .NET Framework 4.8Microsoft .NET Framework 4.6.2

References

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.001

Percentile

39.1%