CVE-2021-24112

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-24112
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24112.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-24112
Aliases
Downstream
Related
Published
2021-02-25T23:15:16.570Z
Modified
2025-11-20T11:36:56.553965Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

.NET Core Remote Code Execution Vulnerability

References

Affected packages

Git / github.com/mono/mono

Affected ranges

Type
GIT
Repo
https://github.com/mono/mono
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

1-1-3
RHYS_20020821
last-commit-with-compulsory-changelog-entry
mono-1-1-3
mono-1-1-9-2
mono-2-2-p2
mono-2-2-p3
mono-2-2-rc1
monotouch-1-4

mono-1.*

mono-1.1.14
mono-1.1.15
mono-1.1.16
mono-1.1.17
mono-1.1.18
mono-1.1.4
mono-1.1.5
mono-1.1.9

mono-2.*

mono-2.11.0
mono-2.11.1
mono-2.11.2
mono-2.11.3
mono-2.11.4
mono-2.2

mono-3.*

mono-3.0.0
mono-3.0.1
mono-3.0.10
mono-3.0.10-windows
mono-3.0.11
mono-3.0.12
mono-3.0.2
mono-3.0.3
mono-3.0.4
mono-3.0.5
mono-3.0.6
mono-3.0.7
mono-3.0.8
mono-3.0.9
mono-3.2.3

mono-6.*

mono-6.12.0.100
mono-6.12.0.101
mono-6.12.0.102
mono-6.12.0.103
mono-6.12.0.105
mono-6.12.0.106
mono-6.12.0.107
mono-6.12.0.109
mono-6.12.0.110
mono-6.12.0.111
mono-6.12.0.112
mono-6.12.0.113
mono-6.12.0.114
mono-6.12.0.86
mono-6.12.0.89
mono-6.12.0.90
mono-6.12.0.91
mono-6.12.0.93
mono-6.12.0.98
mono-6.12.0.99

moon-1.*

moon-1.9.0
moon-1.9.1
moon-1.9.2
moon-1.99.1
moon-1.99.2

moon-2.*

moon-2.99.0.1

moon/2.*

moon/2.99.0.4
moon/2.99.0.5
moon/2.99.0.6
moon/2.99.0.7
moon/2.99.0.8

moon/3.*

moon/3.99.0.1
moon/3.99.0.2

Database specific

vanir_signatures

[
    {
        "signature_type": "Function",
        "deprecated": false,
        "target": {
            "file": "mono/metadata/w32process-unix.c",
            "function": "ves_icall_System_Diagnostics_Process_ShellExecuteEx_internal"
        },
        "digest": {
            "length": 2461.0,
            "function_hash": "332023839309420136721454079539944412274"
        },
        "source": "https://github.com/mono/mono/commit/c621c35ffa03273dbfb83055c7587c6a6617295a",
        "signature_version": "v1",
        "id": "CVE-2021-24112-a59c3744"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "target": {
            "file": "mono/metadata/w32process-unix.c"
        },
        "digest": {
            "line_hashes": [
                "187426045632673110241050639906851923092",
                "333043911263186902062214262369590588592",
                "106389573904973060940279976284525218914",
                "140061867908977381045271417549231451709",
                "164227915027203989860172366370028994699",
                "285677462648598166348343002929535890844",
                "324916490189673593790121382141420535453",
                "170179510509968663814232146624248700046",
                "66152540540530829369605937576243742056",
                "67575751260332271859057486015146050446",
                "41292935628389076826433496871707273805",
                "178483287709880595691649165559221994767",
                "261188484371964551150085603238646450321",
                "152321120229093870526445324093733590334"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/mono/mono/commit/c621c35ffa03273dbfb83055c7587c6a6617295a",
        "signature_version": "v1",
        "id": "CVE-2021-24112-f1522214"
    }
]