CVE-2024-35264 is a Remote Code Execution (RCE) vulnerability affecting Microsoft .NET and Visual Studio 2022. Rated 8.1 HIGH on CVSS, this flaw can be exploited remotely with high impact on confidentiality, integrity, and availability, though it requires high attack complexity and no user interaction. While not currently listed in CISA's KEV catalog and lacking public exploit code, its high FAUCET Risk Score and notable community discussion and media coverage suggest it warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.0.7CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 17.4.0, < 17.4.21CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.6.0, < 17.6.17CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.8.0, < 17.8.12CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.10.0, < 17.10.4CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
Jul 9, 2024.NET and Visual Studio Remote Code Execution Vulnerability
Jul 9, 2024dotnet: DoS in ASP.NET Core 8
Jul 9, 2024