Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2947 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability |
Github GHSA |
GHSA-c3hf-8vgx-72rh | Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability |
Ubuntu USN |
USN-6480-1 | .NET vulnerabilities |
Wed, 01 Jan 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:.net:3.0:sp2:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:3.5.1:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:3.5:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:4.6.2:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:4.7.2:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:4.8.1:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:4.8:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio:2022:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2022:17.2:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2022:17.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft visual Studio
|
Subscriptions
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-10-09T00:00:12.865Z
Reserved: 2023-06-20T20:44:39.829Z
Link: CVE-2023-36049
No data.
Status : Modified
Published: 2023-11-14T21:15:10.083
Modified: 2026-06-17T06:05:44.437
Link: CVE-2023-36049
OpenCVE Enrichment
No data.
-
CWE-20
Improper Input Validation
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
- NVD-CWE-noinfo
EUVD
Github GHSA
Ubuntu USN