VYPR
High severity7.8NVD Advisory· Published Sep 12, 2023· Updated Jun 17, 2026

CVE-2023-36796

CVE-2023-36796

Description

Visual Studio Remote Code Execution Vulnerability

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.NETCore.App.Runtime.win-arm64NuGet
>= 7.0.0, < 7.0.117.0.11
Microsoft.NETCore.App.Runtime.win-arm64NuGet
>= 6.0.0, < 6.0.226.0.22
Microsoft.NETCore.App.Runtime.win-x64NuGet
>= 7.0.0, < 7.0.117.0.11
Microsoft.NETCore.App.Runtime.win-x64NuGet
>= 6.0.0, < 6.0.226.0.22
Microsoft.NETCore.App.Runtime.win-x86NuGet
>= 6.0.0, < 6.0.226.0.22
Microsoft.NETCore.App.Runtime.win-x86NuGet
>= 7.0.0, < 7.0.117.0.11

Affected products

43
  • Microsoft/Microsoft Visual Studio 2022 version 17.6v5
    Range: 17.6.0
  • Microsoft/Microsoft Visual Studio 2022 version 17.7v5
    Range: 17.7.0
  • Microsoft/Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)v5
    Range: 15.9.0
  • Microsoft/Microsoft Visual Studio 2022 version 17.2v5
    Range: 17.2.0
  • Microsoft/Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)v5
    Range: 16.11.0
  • Microsoft/Microsoft Visual Studio 2022 version 17.4v5
    Range: 17.4.0
  • Microsoft/Microsoft Visual Studio 2013 Update 5v5
    Range: 12.0.0
  • Microsoft/Microsoft Visual Studio 2015 Update 3v5
    Range: 14.0.0
  • Microsoft/.NET 7.0v5
    Range: 7.0.0
  • Microsoft/.NET 6.0v5
    Range: 6.0.0
  • cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*
    • (no CPE)range: 4.8.0
    • (no CPE)range: 4.8.0
    • (no CPE)range: 4.7.0
    • (no CPE)range: 3.0.0.0
    • (no CPE)range: 4.7.0
    • (no CPE)range: 4.8.1
    • (no CPE)range: 4.7.0
    • (no CPE)range: 4.7.0
    • (no CPE)range: 2.0.0
    • (no CPE)range: 3.0.0
    • (no CPE)range: 3.5.0
    • (no CPE)range: 3.5.0
  • Microsoft/Net2 versions
    cpe:2.3:a:microsoft:.net:6.0.0:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:.net:6.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net:7.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*
    Range: >=15.0,<15.9.57
  • cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*range: >=16.0,<16.11.30
    • cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*range: >=17.2,<17.2.19
  • ghsa-coords5 versions
    >= 7.0.0, < 7.0.11+ 4 more
    • (no CPE)range: >= 7.0.0, < 7.0.11
    • (no CPE)range: >= 7.0.0, < 7.0.11
    • (no CPE)range: >= 6.0.0, < 6.0.22
    • (no CPE)range: >= 6.0.0, < 6.0.1
    • (no CPE)range: >= 6.0.0, < 6.0.1
  • Range: 7.2.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.