QID 92078
Date Published: 2023-11-15
QID 92078: Microsoft .NET Framework Update for November 2023
A Remote Code Execution Vulnerability exist in Microsoft .Net Framework.
Following KBs are covered in this detection:
5032004
5032336
5032337
5032197
5031989
5032343
5032342
5032344
5032186
5032341
5032185
5032340
5032007
5032199
5032339
5032338
This security update is rated Important for supported versions of Microsoft .NET Framework.
.NET Framework 2.0, 3.0, 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1
QID Detection Logic (Authenticated):
Checks for vulnerable file version of ntoskrnl.exe or Mscorlib.dll or System.core.dll or System.web.dll for the respective .Net Framework KBs
Successful exploitation may allow a attacker to perform Elevation of Privileges.
Solution
Customers are advised to refer to CVE-2023-36049, CVE-2023-36560 for more details pertaining to these vulnerabilities.
Vendor References
- 5031989 -
support.microsoft.com/en-us/topic/november-14-2023-kb5031989-cumulative-update-for-net-framework-4-8-for-windows-10-version-1607-and-windows-server-2016-016cab6a-0bfd-407d-8718-3a4b1af65e0e - 5032004 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032004-cumulative-update-for-net-framework-3-5-and-4-8-1-for-microsoft-server-operating-system-version-23h2-e3c9b0d9-ec46-4e8e-ba87-6c831bc11ef3 - 5032007 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032007-cumulative-update-for-net-framework-3-5-and-4-8-1-for-windows-11-version-22h2-and-windows-11-version-23h2-e7198982-9236-4bc2-a76a-42efb7f2a3b5 - 5032185 -
support.microsoft.com/en-us/topic/november-14-2023-security-only-update-for-net-framework-3-5-1-4-6-2-4-7-4-7-1-4-7-2-4-8-for-windows-embedded-7-standard-and-windows-server-2008-r2-sp1-kb5032185-78eb8c4f-bd90-4208-9218-7e6aa0481195 - 5032186 -
support.microsoft.com/en-us/topic/november-14-2023-security-only-update-for-net-framework-2-0-3-0-4-6-2-for-windows-server-2008-sp2-kb5032186-fbd4c8e6-3f97-4fec-b7f1-1a3e71834095 - 5032197 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032197-os-build-14393-6452-7eff4948-a9bb-46ba-aa91-ce3047cac846 - 5032199 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032199-os-build-10240-20308-ae103d5c-6d34-4ac7-a4a4-85e37cdb389b - 5032336 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032336-cumulative-update-for-net-framework-3-5-4-8-and-4-8-1-for-windows-server-2022-4fbab26b-493a-4ee5-9766-d6448e73bfb1 - 5032337 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032337-cumulative-update-for-net-framework-3-5-4-7-2-and-4-8-for-windows-10-version-1809-and-windows-server-2019-88c7eaec-1df7-4759-9230-77879852eb7c - 5032338 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032338-cumulative-update-for-net-framework-3-5-4-8-and-4-8-1-for-windows-10-version-21h2-29411f34-09a6-4f0e-b0af-6995cb232295 - 5032339 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032339-cumulative-update-for-net-framework-3-5-4-8-and-4-8-1-for-windows-10-version-22h2-5a292b74-4189-4c79-92f5-9f91544142ad - 5032340 -
support.microsoft.com/en-us/topic/november-14-2023-kb5032340-cumulative-update-for-net-framework-3-5-4-8-and-4-8-1-for-windows-11-version-21h2-84d17995-f6d7-48ca-93bb-7b8c7b3ee43c - 5032341 -
support.microsoft.com/en-us/topic/november-14-2023-security-and-quality-rollup-for-net-framework-3-5-1-4-6-2-4-7-4-7-1-4-7-2-4-8-for-windows-embedded-7-standard-and-windows-server-2008-r2-sp1-kb5032341-572996ff-2095-4062-be9e-3e6e23d0415f - 5032342 -
support.microsoft.com/en-us/topic/november-14-2023-security-and-quality-rollup-for-net-framework-3-5-4-6-2-4-7-4-7-1-4-7-2-4-8-for-windows-server-2012-kb5032342-5cfb9964-edb1-4eec-b1f9-197b663ef55b - 5032343 -
support.microsoft.com/en-us/topic/november-14-2023-security-and-quality-rollup-for-net-framework-3-5-4-6-2-4-7-4-7-1-4-7-2-4-8-for-windows-server-2012-r2-kb5032343-e469dac3-52ac-47ee-8d80-037af14dc2c8 - 5032344 -
support.microsoft.com/en-us/topic/november-14-2023-security-and-quality-rollup-for-net-framework-2-0-3-0-4-6-2-for-windows-server-2008-sp2-kb5032344-37ca41f5-d4b1-444b-a9f5-f2f7a93f3257
CVEs related to QID 92078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-36049 |
|
||
| CVE-2023-36560 |
|