s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-21808

📛 CVE Title

.NET and Visual Studio Remote Code Execution Vulnerability

Description

.NET and Visual Studio Remote Code Execution Vulnerability

Overview

State
PUBLISHED
Assigner (CNA)
microsoft
CVSS severity
HIGH
CVSS score
CVSS 7.8 / 10 7.8 7.8 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Effective score
7.8 / 10 HIGH source: CNA overview
MSRC score
8.4 / 10 HIGH MS rating: Critical · Remote Code Execution
CWE(s)
CWE-416
Reserved
2022-12-16
Published
2023-02-14 08:00 UTC
Last updated
2023-06-30 07:00 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21808.json
Linked Threat
CVE-2023-21808 — .NET and Visual Studio Remote Code Execution Vulnerability

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-0660
Assigner
microsoft
Published
Feb 14, 2023, 8:09:27 PM
Updated
Feb 28, 2025, 9:13:45 PM
EUVD base score (CVSS 3.1)
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EUVD-reported EPSS
1.2800
Vendors
Microsoft
Products
Microsoft Visual Studio 2022 version 17.2 (17.2.0 <17.2.13)
Microsoft .NET Framework 3.5 AND 4.7.2 (4.7.0 <10.0.04038.03)
Microsoft Visual Studio 2022 version 17.0 (17.0.0 <17.0.19)
Microsoft .NET Framework 3.5 AND 4.8 (4.8.0 <10.0.04614.06)
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) (15.9.0 <15.9.52)
.NET 7.0 (7.0.0 <7.0.3)
Microsoft Visual Studio 2015 Update 3 (14.0.0 <14.0.27555.0)
Microsoft .NET Framework 4.6.2 (4.7.0 <4.7.04038.06)
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 (4.7.0 <4.7.04614.08)
Microsoft .NET Framework 3.5 and 4.6.2 (4.7.0 <10.0.10240.19747)
PowerShell 7.2 (7.2.0 <7.2.10)
Microsoft .NET Framework 3.5 AND 4.8.1 (4.8.1 <10.0.09139.02)
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) (16.11.0 <16.11.24)
Microsoft Visual Studio 2022 version 17.4 (17.4.0 <17.4.5)
.NET 6.0 (6.0.0 <6.0.14)
Microsoft Visual Studio 2013 Update 5 (12.0.0 <12.0.40700.0)
Microsoft .NET Framework 4.8 (4.8.0 <4.8.04614.05)
Aliases
GHSA-824j-wqm8-89mj

ENISA description: .NET and Visual Studio Remote Code Execution Vulnerability

EUVD references (1)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 01:49 UTC (source: CVRF).

MS severity
Critical
Impact
Remote Code Execution
MS CVSS base score
8.4 / 10 (temporal 7.3)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Exploit assessment
Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Release
2023-Feb
Microsoft remediations / KB articles (50)
  • Release Notes — Vendor Fix / Security Update (fixed build 16.11.24)
  • Release Notes — Vendor Fix / Security Update (fixed build 17.0.19)
  • Release Notes — Vendor Fix / Security Update (fixed build 15.9.52)
  • Release Notes — Vendor Fix / Security Update (fixed build 17.4.5)
  • Release Notes — Vendor Fix / Security Update (fixed build 17.2.13)
  • 5025792 — Vendor Fix / Security Update (fixed build 14.0.27555.0)
  • 5026610 — Vendor Fix / Security Update (fixed build 12.0.40700.0)
  • 5023286 — Vendor Fix / Security Update (fixed build 7.0.3)
  • 5023288 — Vendor Fix / Security Update (fixed build 6.0.14)
  • Release Notes — Vendor Fix / Security Update (fixed build 7.2.10)
  • 5022782 — Vendor Fix / Security Update (fixed build 10.0.04614.06)
  • 5022782 — Update
  • 5022735 — Vendor Fix / Security Update (fixed build 10.0.04614.06)
  • 5022735 — Update
  • 5022727 — Vendor Fix / Security Update (fixed build 10.0.04614.06)
  • 5022727 — Update
  • 5022730 — Vendor Fix / Security Update (fixed build 10.0.4614.06)
  • 5022730 — Update
  • 5022728 — Update
  • 5022782 — Vendor Fix / Security Update (fixed build 10.0.04038.03)
  • 5022731 — Vendor Fix / Monthly Rollup (fixed build 4.7.04614.08)
  • 5022731 — Update
  • 5022783 — Vendor Fix / Security Only (fixed build 4.7.04038.05)
  • 5022783 — Update
  • 5022732 — Vendor Fix / Monthly Rollup (fixed build 4.7.04038.03)
  • 5022732 — Update
  • 5022784 — Vendor Fix / Security Only (fixed build 4.7.04038.02)
  • 5022784 — Update
  • 5022733 — Vendor Fix / Monthly Rollup (fixed build 4.8.04614.05)
  • 5022733 — Update
  • 5022785 — Vendor Fix / Security Only (fixed build 4.8.04614.03)
  • 5022785 — Update
  • 5022731 — Vendor Fix / Monthly Rollup (fixed build 4.8.4614.08)
  • 5022783 — Vendor Fix / Security Only (fixed build 4.8.4614.07)
  • 5022733 — Vendor Fix / Monthly Rollup (fixed build 4.7.04038.03)
  • 5022785 — Vendor Fix / Security Only (fixed build 4.7.04038.02)
  • 5022732 — Vendor Fix / Monthly Rollup (fixed build 4.8.04614.05)
  • 5022784 — Vendor Fix / Security Only (fixed build 4.8.04614.03)
  • 5022735 — Vendor Fix / Security Update (fixed build 10.0.09139.02)
  • 5022727 — Vendor Fix / Security Update (fixed build 10.0.09139.02)
  • 5022730 — Vendor Fix / Security Update (fixed build 10.0.09139.02)
  • 5022729 — Update
  • 5022497 — Vendor Fix / Security Update (fixed build 10.0.09139.02)
  • 5022497 — Update
  • 5022734 — Update
  • 5022786 — Update
  • 5022858 — Vendor Fix / Security Update (fixed build 10.0.10240.19747)
  • 5022838 — Vendor Fix / Security Update (fixed build 10.0.14393.5717)
  • 5022503 — Vendor Fix / Security Update (fixed build 10.0.04614.05)
  • 5022503 — Update
Microsoft FAQ (2)

According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?

The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.

According to the CVSS metrics, there are multiple scores. Why does the CVE have different scores and different severities for different products?

There are different scores depending on the product due to the way symbols are read and parsed. Visual Studio has the ability to automatically query symbol servers while .NET only uses symbols present on the disk, requiring the user to manually query the symbol.

Affected products (17)

VendorProductVersionsPlatforms
Microsoft Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) 16.11.0 (affected) Unknown
Microsoft Microsoft Visual Studio 2022 version 17.0 17.0.0 (affected) Unknown
Microsoft Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) 15.9.0 (affected) Unknown
Microsoft Microsoft Visual Studio 2022 version 17.4 17.4.0 (affected) Unknown
Microsoft Microsoft Visual Studio 2022 version 17.2 17.2.0 (affected) Unknown
Microsoft Microsoft Visual Studio 2015 Update 3 14.0.0 (affected) Unknown
Microsoft Microsoft Visual Studio 2013 Update 5 12.0.0 (affected) Unknown
Microsoft .NET 7.0 7.0.0 (affected) Unknown
Microsoft .NET 6.0 6.0.0 (affected) Unknown
Microsoft PowerShell 7.2 7.2.0 (affected) Unknown
Microsoft Microsoft .NET Framework 3.5 AND 4.8 4.8.0 (affected) Windows 10 Version 1809 for 32-bit Systems, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 20H2 for ARM64-based Systems, Windows 10 Version 20H2 for 32-bit Systems, Windows 11 version 21H2 for x64-based Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 11 version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 21H2 for 32-bit Systems, Windows Server 2022 (Server Core installation), Windows Server 2019, Windows 10 Version 1809 for x64-based Systems, Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2 for 32-bit Systems
Microsoft Microsoft .NET Framework 3.5 AND 4.7.2 4.7.0 (affected) Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for ARM64-based Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1607 for x64-based Systems, Windows 10 Version 1607 for 32-bit Systems, Windows Server 2016
Microsoft Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 4.7.0 (affected) Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft Microsoft .NET Framework 4.8 4.8.0 (affected) Windows Server 2012 R2 (Server Core installation), Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2012
Microsoft Microsoft .NET Framework 3.5 AND 4.8.1 4.8.1 (affected) Windows Server 2022 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2 for 32-bit Systems, Windows 10 Version 20H2 for ARM64-based Systems, Windows 11 version 21H2 for x64-based Systems, Windows 10 Version 21H2 for 32-bit Systems, Windows 11 version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for x64-based Systems
Microsoft Microsoft .NET Framework 4.6.2 4.7.0 (affected) Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Microsoft Microsoft .NET Framework 3.5 and 4.6.2 4.7.0 (affected) Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (56)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (14)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:www.microsoft.com

    Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.

    2026-06-04 13:45 UTC
  • web:www.techtarget.com

    Do you know your options for Microsoft patch management? WSUS will not be updated and will most likely disappear in the next Windows Server release.

    2026-06-04 13:45 UTC
  • web:www.bleepingcomputer.com

    Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges.

    2026-06-04 13:45 UTC
  • web:techdocs.broadcom.com

    Patch Category Security Patch Severity Critical Host Reboot Required Yes Virtual Machine Migration or Shutdown Required Yes Affected Hardware N/A Affected Software N/A Affected VIBs Included VMware_bootbank_esxio-update_8..3-.60.24585383 VMware_bootbank_loadesxio_8..3-.60.24585383 PRs Fixed N/A CVE numbers N/A Due to their dependency on the ...

    2026-06-04 13:45 UTC
  • web:www.lansweeper.com

    Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday August 2025 summary.

    2026-05-22 05:46 UTC
  • web:www.ninjaone.com

    Catalog of Microsoft KB updates with insights on performance & user sentiment. Find out what's working, what's not, & make informed decisions.

    2026-05-22 05:46 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-05-22 05:46 UTC
  • web:www.securityweek.com

    Microsoft has rolled out fixes for 83 vulnerabilities in its products, including a critical bug, but none of them require urgent attention.

    2026-05-22 05:46 UTC
  • web:www.zdnet.com

    Install Microsoft's emergency Windows patch now - what it fixes and why it was rushed out Microsoft issued an out-of-band fix after its latest update introduced a nasty surprise.

    2026-05-22 05:46 UTC
  • web:cybersecuritynews.com

    Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

    2026-05-22 05:46 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-05-22 05:46 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 05:46 UTC
  • web:www.bleepingcomputer.com

    Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code.

    2026-05-22 05:46 UTC
  • web:www.computerworld.com

    Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

    2026-05-22 05:46 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2023-21808.json.

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T09:51:50.928Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21808"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-21808",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-28T20:23:13.694036Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-28T21:13:45.998Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "16.11.24",
              "status": "affected",
              "version": "16.11.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2022 version 17.0",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "17.0.19",
              "status": "affected",
              "version": "17.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "15.9.52",
              "status": "affected",
              "version": "15.9.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2022 version 17.4",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "17.4.5",
              "status": "affected",
              "version": "17.4.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2022 version 17.2",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "17.2.13",
              "status": "affected",
              "version": "17.2.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2015 Update 3",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "14.0.27555.0",
              "status": "affected",
              "version": "14.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "Microsoft Visual Studio 2013 Update 5",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "12.0.40700.0",
              "status": "affected",
              "version": "12.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": ".NET 7.0",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "7.0.3",
              "status": "affected",
              "version": "7.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": ".NET 6.0",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "6.0.14",
              "status": "affected",
              "version": "6.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Unknown"
          ],
          "product": "PowerShell 7.2",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "7.2.10",
              "status": "affected",
              "version": "7.2.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows 10 Version 1809 for 32-bit Systems",
            "Windows Server 2022",
            "Windows Server 2019 (Server Core installation)",
            "Windows 10 Version 20H2 for ARM64-based Systems",
            "Windows 10 Version 20H2 for 32-bit Systems",
            "Windows 11 version 21H2 for x64-based Systems",
            "Windows 10 Version 21H2 for ARM64-based Systems",
            "Windows 11 version 21H2 for ARM64-based Systems",
            "Windows 10 Version 21H2 for x64-based Systems",
            "Windows 10 Version 21H2 for 32-bit Systems",
            "Windows Server 2022 (Server Core installation)",
            "Windows Server 2019",
            "Windows 10 Version 1809 for x64-based Systems",
            "Windows 10 Version 1607 for 32-bit Systems",
            "Windows 10 Version 22H2 for x64-based Systems",
            "Windows 10 Version 22H2 for ARM64-based Systems",
            "Windows 10 Version 1607 for x64-based Systems",
            "Windows Server 2016",
            "Windows Server 2016 (Server Core installation)",
            "Windows 10 Version 22H2 for 32-bit Systems"
          ],
          "product": "Microsoft .NET Framework 3.5 AND 4.8",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "10.0.04614.06",
              "status": "affected",
              "version": "4.8.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows 10 Version 1809 for 32-bit Systems",
            "Windows 10 Version 1809 for ARM64-based Systems",
            "Windows 10 Version 1809 for x64-based Systems",
            "Windows Server 2019",
            "Windows Server 2019 (Server Core installation)",
            "Windows Server 2016 (Server Core installation)",
            "Windows 10 Version 1607 for x64-based Systems",
            "Windows 10 Version 1607 for 32-bit Systems",
            "Windows Server 2016"
          ],
          "product": "Microsoft .NET Framework 3.5 AND 4.7.2",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "10.0.04038.03",
              "status": "affected",
              "version": "4.7.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
            "Windows Server 2012 (Server Core installation)",
            "Windows Server 2012",
            "Windows Server 2012 R2 (Server Core installation)",
            "Windows Server 2012 R2",
            "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
          ],
          "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "4.7.04614.08",
              "status": "affected",
              "version": "4.7.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows Server 2012 R2 (Server Core installation)",
            "Windows Server 2008 R2 for x64-based Systems Service Pack 1",
            "Windows Server 2012 R2",
            "Windows Server 2012 (Server Core installation)",
            "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
            "Windows Server 2012"
          ],
          "product": "Microsoft .NET Framework 4.8",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "4.8.04614.05",
              "status": "affected",
              "version": "4.8.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows Server 2022 (Server Core installation)",
            "Windows Server 2022",
            "Windows 10 Version 20H2 for 32-bit Systems",
            "Windows 10 Version 20H2 for ARM64-based Systems",
            "Windows 11 version 21H2 for x64-based Systems",
            "Windows 10 Version 21H2 for 32-bit Systems",
            "Windows 11 version 21H2 for ARM64-based Systems",
            "Windows 10 Version 21H2 for ARM64-based Systems",
            "Windows 10 Version 21H2 for x64-based Systems",
            "Windows 11 Version 22H2 for ARM64-based Systems",
            "Windows 11 Version 22H2 for x64-based Systems",
            "Windows 10 Version 22H2 for ARM64-based Systems",
            "Windows 10 Version 22H2 for 32-bit Systems",
            "Windows 10 Version 22H2 for x64-based Systems"
          ],
          "product": "Microsoft .NET Framework 3.5 AND 4.8.1",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "10.0.09139.02",
              "status": "affected",
              "version": "4.8.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows Server 2008 for 32-bit Systems Service Pack 2",
            "Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)",
            "Windows Server 2008 for x64-based Systems Service Pack 2",
            "Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)"
          ],
          "product": "Microsoft .NET Framework 4.6.2",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "4.7.04038.06",
              "status": "affected",
              "version": "4.7.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "Windows 10 for 32-bit Systems",
            "Windows 10 for x64-based Systems"
          ],
          "product": "Microsoft .NET Framework 3.5 and 4.6.2",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "10.0.10240.19747",
              "status": "affected",
              "version": "4.7.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "16.11.24",
                  "versionStartIncluding": "16.11.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "17.0.19",
                  "versionStartIncluding": "17.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "15.9.52",
                  "versionStartIncluding": "15.9.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "17.4.5",
                  "versionStartIncluding": "17.4.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "17.2.13",
                  "versionStartIncluding": "17.2.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio:*:update3:*:*:*:*:*:*",
                  "versionEndExcluding": "14.0.27555.0",
                  "versionStartIncluding": "14.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:visual_studio:*:update_5:*:*:*:*:*:*",
                  "versionEndExcluding": "12.0.40700.0",
                  "versionStartIncluding": "12.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.3",
                  "versionStartIncluding": "7.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.0.14",
                  "versionStartIncluding": "6.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.10",
                  "versionStartIncluding": "7.2.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "10.0.04614.06",
                  "versionStartIncluding": "4.8.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "10.0.04038.03",
                  "versionStartIncluding": "4.7.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.7.04614.08",
                  "versionStartIncluding": "4.7.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.8.04614.05",
                  "versionStartIncluding": "4.8.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "10.0.09139.02",
                  "versionStartIncluding": "4.8.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.7.04038.06",
                  "versionStartIncluding": "4.7.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "10.0.10240.19747",
                  "versionStartIncluding": "4.7.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "datePublic": "2023-02-14T08:00:00.000Z",
      "descriptions": [
        {
          "lang": "en-US",
          "value": ".NET and Visual Studio Remote Code Execution Vulnerability"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en-US",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-416",
              "description": "CWE-416: Use After Free",
              "lang": "en-US",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-01-01T00:41:01.018Z",
        "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "shortName": "microsoft"
      },
      "references": [
        {
          "name": ".NET and Visual Studio Remote Code Execution Vulnerability",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21808"
        }
      ],
      "title": ".NET and Visual Studio Remote Code Execution Vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
    "assignerShortName": "microsoft",
    "cveId": "CVE-2023-21808",
    "datePublished": "2023-02-14T20:09:27.030Z",
    "dateReserved": "2022-12-16T22:13:41.241Z",
    "dateUpdated": "2025-02-28T21:13:45.998Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}