CVE-2021-24112 is a critical remote code execution vulnerability affecting Microsoft .NET, .NET Core, Mono, and Visual Studio 2019. With a CVSS score of 9.8, it presents a low-complexity attack vector that does not require user interaction, allowing for complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation. Its FAUCET Risk Score of 80/100 further emphasizes its high potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, <= 5.0.2CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 2.1, <= 2.1.24CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:* | ||
>= 3.1, <= 3.1.11CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:* | ||
>= 6.12.0, < 6.12.0.122CPE matchmatch criteria | cpe:2.3:a:microsoft:mono:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:-:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.