CVE-2021-41355: .NET Core and Visual Studio Information Disclosure Vulnerability
Overview
- Severity
- Medium (CVSS 5.7)
- CVSS Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- Category
- Information Disclosure
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2021-Oct
- Released
- 2021-10-12
- Last Updated
- 2021-10-14
- EPSS Score
- 3.61% (percentile: 87.8%)
FAQ
What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.
Affected Products (4)
Developer Tools
- PowerShell 7.1
- Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
- Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
- .NET 5.0
Security Updates (4)
Acknowledgments
Srinivas Nunna of Microsoft
Revision History
- 2021-10-12: Information published.
- 2021-10-14: Revised the Security Updates table to include PowerShell 7.1 because this version of PowerShell 7 incorporates the version of .NET that is affected by this vulnerability. See https://github.com/PowerShell/Announcements/issues/26 for more information.