Permissions, Privileges, and Access Controls in .NET and Visual Studio - CVE-2023-33135
Published: June 13, 2023
Vulnerability identifier: #VU77226
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33135
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in .NET and Visual Studio. A remote user can trick a victim to open a specially crafted file and gain elevated privileges on the system.
Affected software
.NET
SINEC PNI
Visual Studio
Amazon Linux AMI
dotnet6.0
SINEC PNI
Visual Studio
Amazon Linux AMI
dotnet6.0
How to mitigate CVE-2023-33135
Install updates from vendor's website.
SINEC PNI - update to 2.0
dotnet6.0 - update to 6.0.118-1
dotnet6.0 - update to 6.0.118-1