CVE-2023-28260: Microsoft .net

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

.NET DLL Hijacking Remote Code Execution Vulnerability

Affected products

  • Microsoft .net: from 6.0.0, before 6.0.16 (fixed in 6.0.16); from 7.0.0, before 7.0.5 (fixed in 7.0.5)
  • Microsoft Visual Studio 2022: from 17.0, before 17.0.21 (fixed in 17.0.21); from 17.2, before 17.2.15 (fixed in 17.2.15); from 17.4, before 17.4.7 (fixed in 17.4.7); from 17.5, before 17.5.4 (fixed in 17.5.4)

Published 2023-04-11. Last modified 2026-06-17.