CVE-2023-33135 is an Elevation of Privilege vulnerability affecting Microsoft .NET and Visual Studio 2022. With a CVSS score of 7.3 (HIGH), this vulnerability could allow a local attacker to gain elevated privileges if a user is tricked into opening a malicious file. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed in CISA's KEV catalog, there has been limited community discussion and media coverage, indicating some awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.0.18CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.7CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.0.22CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.2, < 17.2.16CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.4, < 17.4.8CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.