CVE-2023-36049: Microsoft .NET CRLF Injection Arbitrary File Write/Deletion Vulnerability
ID: c507f966-ee10-56a4-9e92-869c246008ca
STIX ID: report--c507f966-ee10-56a4-9e92-869c246008ca
Feed Name: Zero Day Initiative (ZDI) Blog
Threat Score
This report analyzes CVE-2023-36049, an FTP-URI handling vulnerability affecting PowerShell (including versions 7.2–7.4) for which Microsoft released patches in November. It gives detection guidance—monitor FTP traffic on TCP/21 and flag packets containing multiple FTP commands (multiple CRLFs)—and recommends applying the vendor patch or refusing/filtering FTP URIs from untrusted peers as mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
