CVE-2021-41355: .NET Core and Visual Studio Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 5.7)
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Oct
Released
2021-10-12
Last Updated
2021-10-14
EPSS Score
3.61% (percentile: 87.8%)

FAQ

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.

Affected Products (4)

Developer Tools

  • PowerShell 7.1
  • Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • .NET 5.0

Security Updates (4)

Acknowledgments

Srinivas Nunna of Microsoft

Revision History

  • 2021-10-12: Information published.
  • 2021-10-14: Revised the Security Updates table to include PowerShell 7.1 because this version of PowerShell 7 incorporates the version of .NET that is affected by this vulnerability. See https://github.com/PowerShell/Announcements/issues/26 for more information.