Vulnerability CVE-2022-41089: Information

Description

.NET Framework Remote Code Execution Vulnerability

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Dec. 13, 2022
Modified: Nov. 17, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dotnet-bootstrap-3.1p103.1.32-alt13.1.32-alt1ALT-PU-2023-1466-1316692Fixed
dotnet-bootstrap-3.1c10f13.1.32-alt13.1.32-alt1ALT-PU-2023-1466-1316692Fixed
dotnet-coreclr-3.1p103.1.32-alt13.1.32-alt1ALT-PU-2023-1467-1316692Fixed
dotnet-coreclr-3.1c10f13.1.32-alt13.1.32-alt1ALT-PU-2023-1467-1316692Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_7:sp1:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:*

      Configuration 6

      cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

      Configuration 7

      cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

      Configuration 8

      cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2008:sp2:*:*:*:*:*:*:*

      Configuration 9

      cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*

      Configuration 10

      cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*

      cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*