Threat Advisory

Microsoft .NET CRLF Injection Arbitrary File Write/Deletion Vulnerability

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

The Researchers Team outlines a privilege escalation flaw in .NET Framework and Visual Studio, the vulnerability, identified as CVE-2023-36049, could enable a remote attacker to manipulate files within the FTP server's context. The .NET Framework facilitates software development and execution on Windows systems, utilizing the Common Language Runtime (CLR) for application execution. FTP, described in RFC 959, employs separate TCP connections for control and data transfer, with commands exchanged between the client and server.[/subscribe_to_unlock_form]

Summary:

The Researchers Team outlines a privilege escalation flaw in .NET Framework and Visual Studio, the vulnerability, identified as CVE-2023-36049, could enable a remote attacker to manipulate files within the FTP server's context. The .NET Framework facilitates software development and execution on Windows systems, utilizing the Common Language Runtime (CLR) for application execution. FTP, described in RFC 959, employs separate TCP connections for control and data transfer, with commands exchanged between the client and server.[emaillocker id="1283"]

The vulnerability stems from inadequate validation of FTP command parameters and URI requests within the .NET Framework. Specifically, functions like FtpControlStream and FtpWebRequest fail to properly validate parameters, potentially allowing for command injection attacks. Malicious FTP requests could lead to unauthorized file manipulation on the FTP server.

The .NET Framework and Visual Studio vulnerability CVE-2023-36049) discovered by researchers highlights critical flaws in FTP command validation, enabling remote attackers to manipulate files. Microsoft's patch, though revised, emphasizes the urgency of proactive mitigation measures to safeguard systems from potential exploitation.

Recommendations:

We strongly recommend you apply an update for .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability.

References:

The following reports contain further technical details:

https://www.zerodayinitiative.com/blog/2024/3/6/cve-2023-36049-microsoft-net-crlf-injection-arbitrary-file-writedeletion-vulnerability

[/emaillocker]
crossmenu