CVE-2021-41355 is an information disclosure vulnerability affecting Microsoft .NET Core, Visual Studio 2019, and PowerShell. This medium-severity flaw (CVSS 5.7) requires adjacent network access and user interaction (UI:R) for an attacker to potentially disclose sensitive information. While not actively exploited (KEV: No) and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:5.0:*:*:*:*:*:*:* | ||
>= 7.1, < 7.1.5CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:* | ||
>= 16.0, <= 16.11CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Credential Disclosure in System.DirectoryServices.Protocols
Oct 12, 2021dotnet: System.DirectoryServices.Protocols.LdapConnection sends credentials in plaintext if TLS handshake fails
Oct 12, 2021.NET Core and Visual Studio Information Disclosure Vulnerability
Oct 12, 2021