CVE-2023-36796: Microsoft .net

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Visual Studio Remote Code Execution Vulnerability

Affected products

  • Microsoft .net: version 6.0.0 only; version 7.0.0 only
  • Microsoft .NET Framework: version 3.5.1 only; version 3.5 only; version 2.0 only; version 3.0 only; version 4.6.2 only; version 4.8 only; …
  • Microsoft Visual Studio 2017: from 15.0, before 15.9.57 (fixed in 15.9.57)
  • Microsoft Visual Studio 2019: from 16.0, before 16.11.30 (fixed in 16.11.30)
  • Microsoft Visual Studio 2022: from 17.2, before 17.2.19 (fixed in 17.2.19); from 17.4, before 17.4.11 (fixed in 17.4.11); from 17.7, before 17.7.4 (fixed in 17.7.4)

Published 2023-09-12. Last modified 2026-06-17.