Microsoft .NET Framework CVE-2022-41089 Remote Code Execution Vulnerability
Description
Remote Code Execution vulnerability in .NET Framework, .NET, and PowerShell 7.2/7.3 allows a local attacker to execute arbitrary code via crafted input, affecting Windows Server 2022, Windows 10, and .NET Framework 3.5/4.8.1.
Affected Applications
.NET 7.0
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows RT 8.1
Microsoft .NET Framework 4.8 on Windows RT 8.1
Microsoft Visual Studio 2022 version 17.4
Microsoft Visual Studio 2022 version 17.2
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Windows Server 2016
Windows Server 2022
Windows Server 2012
Windows 8
Windows 7
Windows 10
Windows Server 2008
Microsoft Visual Studio 2022 version 17.0
.NET 6.0
.NET Core 3.1
Windows 11
Windows Server 2019
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2022-12-14 | 1.00363 |
New
|
. NET 7. 0,Microsoft . NET Framework 4. 6. 2/4. 7/4. 7. 1/4. 7. 2 on Windows RT 8. 1,Microsoft . NET Framework 4. 8 on Windows RT 8. 1,Microsoft Visual Studio 2022 version 17. 4,Microsoft Visual Studio 2022 version 17. 2,Microsoft Visual Studio 2019 version 16. 11 (includes 16. 0 - 16. 10),Windows Server 2016,Windows Server 2022,Windows Server 2012,Windows 8,Windows 7,Windows 10,Windows Server 2008,Microsoft Visual Studio 2022 version 17. 0,. NET 6. 0,. NET Core 3. 1,Windows 11,Windows Server 2019 |