CVE-2024-35264

Name
CVE-2024-35264
Description
.NET and Visual Studio Remote Code Execution Vulnerability
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35264
af854a3a-2127-422b-91ae-364da2661108 https://www.herodevs.com/vulnerability-directory/cve-2024-35264

Match rules

CPE URI Source package Min version Max version
.net-6.0 == N/A == N/A
.net-8.0 >= 1.0.0 < 8.0.7
microsoft-visual-studio-2022-version-17.4 >= 17.4.0 < 17.4.21
microsoft-visual-studio-2022-version-17.8 >= 17.8.0 < 17.8.12
microsoft-visual-studio-2022-version-17.10 >= 17.10 < 17.10.4
microsoft-visual-studio-2022-version-17.6 >= 17.6.0 < 17.6.17

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dotnet8-runtime edge-community 8.0.7-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet8-runtime 3.22-community 8.0.7-r0 None fixed
dotnet8-runtime 3.21-community 8.0.7-r0 None fixed
dotnet8-runtime 3.20-community 8.0.7-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed