CVE-2022-41032
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/10/2022
Last modified:
28/02/2025
Description
NuGet Client Elevation of Privilege Vulnerability
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:.net:6.0.0:-:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:.net_core:3.1:-:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.9.26 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | 16.10.0 (including) | 16.11.20 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | 17.0 (including) | 17.0.15 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | 17.2.0 (including) | 17.2.9 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:* | 17.3 (including) | 17.3.6 (excluding) |
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:macos:*:* | 17.3 (including) | 17.3.7 (excluding) |
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41032
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FOG35Z5RL5W5RGLLYLN46CI4D2UPDSWM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDPT2MJC3HD7HYZGASOOX6MTDR4ASBL5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X7BMHO5ITRBZREVTEKHQRGSFRPDMALV3/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41032