Microsoft Security Advisory CVE-2023-36792: .NET Remote Code Execution Vulnerability
<a name="executive-summary"></a>Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in Microsoft.DiaSymReader.Native.amd64.dll when reading a corrupted PDB file which may lead to remote code execution. This issue only affects Windows systems.
Note: The vulnerabilities CVE-2023-36792, CVE-2023-36793, CVE-2023-36792, CVE-2023-36796 are all resolved by a single patch. Get affected software to resolve all of them.
Discussion
Discussion for this issue can be found at https://github.com/dotnet/runtime/issues/91944
<a name="mitigation-factors"></a>Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
<a name="affected-software"></a>Affected software
- Any .NET 7.0 application running on .NET 7.0.10 or earlier.
- Any .NET 6.0 application running on .NET 6.0.21 or earlier.
If your application uses the following package versions, ensure you update to the latest version of .NET.
<a name=".NET 7"></a>.NET 7
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
Microsoft.NETCore.App.Runtime.win-arm64 | >= 7.0.0, <= 7.0.10 | 7.0.11
Microsoft.NETCore.App.Runtime.win-x64 | >= 7.0.0, <= 7.0.10 | 7.0.11
Microsoft.NETCore.App.Runtime.win-x86 | >= 7.0.0, <= 7.0.10 | 7.0.11