Use-after-free in Microsoft products - CVE-2024-21409
Published: April 10, 2024
Vulnerability identifier: #VU88430
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21409
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in .NET, .NET Framework and Visual Studio. A remote user can execute arbitrary code on the target system.
Affected software
Microsoft .NET Framework
.NET
Visual Studio
Amazon Linux AMI
dotnet6.0
.NET
Visual Studio
Amazon Linux AMI
dotnet6.0
How to mitigate CVE-2024-21409
Install updates from vendor's website.
dotnet6.0 - update to 6.0.129-1