dotnet / announcements

Subscribe to this repo to be notified of Announcements and changes in .NET Core.
Creative Commons Attribution 4.0 International
1.29k stars 44 forks source link

Microsoft Security Advisory CVE-2022-24512 | .NET Remote Code Execution Vulnerability #213

Open dcwhittaker opened 2 years ago

dcwhittaker commented 2 years ago

Microsoft Security Advisory CVE-2022-24512 | .NET Remote Code Execution Vulnerability

Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0, and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A Remote Code Execution vulnerability exists in .NET 6.0, .NET 5.0, and .NET Core 3.1 where a stack buffer overrun occurs in .NET Double Parse routine.

Discussion

Discussion for this issue can be found at https://github.com/dotnet/runtime/issues/66348

Mitigation factors

Microsoft has not identified any mitigating factors for this vulnerability.

Affected software