Lucene search

K
mscveMicrosoftMS:CVE-2021-34532
HistoryAug 10, 2021 - 7:00 a.m.

ASP.NET Core and Visual Studio Information Disclosure Vulnerability

2021-08-1007:00:00
Microsoft
msrc.microsoft.com
82
asp.net
visual studio
information disclosure
vulnerability

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.5%

Affected configurations

Vulners
Node
microsoftvisual_studio_2019Range<8.10.7
OR
microsoftvisual_studio_2019Range<16.10.5
OR
microsoftvisual_studio_2019Range<16.9.10
OR
microsoftvisual_studio_2019Range<16.7.18
OR
microsoftvisual_studio_2019Range<16.4.25
OR
microsoftasp.net_coreRange<5.0.9
OR
microsoftasp.net_coreRange<3.1.18
OR
microsoftasp.net_coreRange<2.1.29
VendorProductVersionCPE
microsoftvisual_studio_2019*cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
microsoftasp.net_core*cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.5%