Skip to content

[GHSA-38fq-h5hc-gwv8] Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability - #9230

Open
kgnio wants to merge 1 commit into
kgnio/advisory-improvement-9230from
kgnio-GHSA-38fq-h5hc-gwv8
Open

[GHSA-38fq-h5hc-gwv8] Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability#9230
kgnio wants to merge 1 commit into
kgnio/advisory-improvement-9230from
kgnio-GHSA-38fq-h5hc-gwv8

Conversation

@kgnio

@kgnio kgnio commented Aug 27, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • CWEs
  • Description

Comments
The advisory is missing the CWE classification currently provided by the CVE's CNA, and its description contains a small CVE identifier typo.
Microsoft Corporation added CWE-191 (Integer Underflow / Wrap or Wraparound) to CVE-2023-36794 on May 28, 2024. The GitHub Advisory Database entry currently has no CWE assigned.
This change adds:
CWE-191 — Integer Underflow (Wrap or Wraparound)
Additionally, the advisory description currently lists CVE-2023-36792 twice in the note describing the related vulnerabilities. The third entry links to CVE-2023-36794 but its visible label incorrectly says CVE-2023-36792.
This change corrects the visible label from:
CVE-2023-36792
to:
CVE-2023-36794
The underlying link already points to CVE-2023-36794.

Reference:

@github-actions
github-actions Bot changed the base branch from main to kgnio/advisory-improvement-9230 August 27, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant