High severity7.8NVD Advisory· Published Aug 8, 2023· Updated Aug 10, 2026
CVE-2023-35390
CVE-2023-35390
Description
.NET and Visual Studio Remote Code Execution Vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.NET.Build.ContainersNuGet | < 7.0.307 | 7.0.307 |
Affected products
31- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:*Range: >=17.2.0,<17.2.18
- osv-coords24 versionspkg:bitnami/dotnetpkg:bitnami/dotnet-sdkpkg:nuget/microsoft.net.build.containerspkg:rpm/almalinux/aspnetcore-runtime-6.0pkg:rpm/almalinux/aspnetcore-runtime-7.0pkg:rpm/almalinux/aspnetcore-targeting-pack-6.0pkg:rpm/almalinux/aspnetcore-targeting-pack-7.0pkg:rpm/almalinux/dotnetpkg:rpm/almalinux/dotnet-apphost-pack-6.0pkg:rpm/almalinux/dotnet-apphost-pack-7.0pkg:rpm/almalinux/dotnet-hostpkg:rpm/almalinux/dotnet-hostfxr-6.0pkg:rpm/almalinux/dotnet-hostfxr-7.0pkg:rpm/almalinux/dotnet-runtime-6.0pkg:rpm/almalinux/dotnet-runtime-7.0pkg:rpm/almalinux/dotnet-sdk-6.0pkg:rpm/almalinux/dotnet-sdk-6.0-source-built-artifactspkg:rpm/almalinux/dotnet-sdk-7.0pkg:rpm/almalinux/dotnet-sdk-7.0-source-built-artifactspkg:rpm/almalinux/dotnet-targeting-pack-6.0pkg:rpm/almalinux/dotnet-targeting-pack-7.0pkg:rpm/almalinux/dotnet-templates-6.0pkg:rpm/almalinux/dotnet-templates-7.0pkg:rpm/almalinux/netstandard-targeting-pack-2.1
>= 6.0.0, < 6.0.21+ 23 more
- (no CPE)range: >= 6.0.0, < 6.0.21
- (no CPE)range: >= 6.0.0, < 6.0.21
- (no CPE)range: < 7.0.307
- (no CPE)range: < 6.0.21-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 6.0.21-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 7.0.110-1.el8_8
- (no CPE)range: < 6.0.21-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 6.0.21-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 6.0.21-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 6.0.121-1.el9_2
- (no CPE)range: < 6.0.121-1.el9_2
- (no CPE)range: < 7.0.110-1.el9_2
- (no CPE)range: < 7.0.110-1.el9_2
- (no CPE)range: < 6.0.21-1.el9_2
- (no CPE)range: < 7.0.10-1.el9_2
- (no CPE)range: < 6.0.121-1.el9_2
- (no CPE)range: < 7.0.110-1.el9_2
- (no CPE)range: < 7.0.110-1.el9_2
- Microsoft/.NET 6.0v5Range: 6.0.0
- Microsoft/.NET 7.0v5Range: 7.0.0
- Microsoft/Microsoft Visual Studio 2022 version 17.2v5Range: 17.2.0
- Microsoft/Microsoft Visual Studio 2022 version 17.4v5Range: 17.4.0
- Microsoft/Microsoft Visual Studio 2022 version 17.6v5Range: 17.6.0
Patches
Vulnerability mechanics
References
9- msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35390nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-p8rx-fwgq-rh2fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-35390ghsaADVISORY
- github.com/dotnet/announcements/issues/266ghsaWEB
- github.com/dotnet/sdk/security/advisories/GHSA-p8rx-fwgq-rh2fghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2VghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKYghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY/nvd
News mentions
0No linked articles in our index yet.