{"id":"CVE-2021-24112","details":".NET Core Remote Code Execution Vulnerability","aliases":["BIT-dotnet-2021-24112","BIT-dotnet-sdk-2021-24112","GHSA-rxg9-xrhp-64gj"],"modified":"2026-04-11T13:53:57.809466Z","published":"2021-02-25T23:15:16.570Z","related":["openSUSE-SU-2024:11556-1"],"references":[{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-24112"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dotnet/core","events":[{"introduced":"62bcac3998e1168f4a34b775a06d6451b5ffca7b"},{"last_affected":"b8c6583af496dab539edbbb2f46f1c6f62538165"},{"introduced":"e7dd0cd3ff917f087f7af2163006d7df6827438b"},{"last_affected":"b8c6583af496dab539edbbb2f46f1c6f62538165"},{"introduced":"5c0a0489d157ca82fca6f9b73c682f118e8c4a8a"},{"last_affected":"b8c6583af496dab539edbbb2f46f1c6f62538165"}],"database_specific":{"versions":[{"introduced":"5.0"},{"last_affected":"5.0.2"},{"introduced":"2.1"},{"last_affected":"2.1.24"},{"introduced":"3.1"},{"last_affected":"3.1.11"}]}},{"type":"GIT","repo":"https://github.com/mono/mono","events":[{"introduced":"0"},{"fixed":"c621c35ffa03273dbfb83055c7587c6a6617295a"}],"database_specific":{"versions":[{"introduced":"6.12.0"},{"fixed":"6.12.0.122"}]}}],"versions":["1-1-3","mono-1-1-3","mono-1.1.14","mono-1.1.15","mono-1.1.16","mono-1.1.17","mono-1.1.18","mono-1.1.4","mono-1.1.5","mono-1.1.9","mono-2.11.0","mono-2.11.1","mono-2.11.2","mono-2.11.3","mono-2.11.4","mono-3.0.0","mono-3.0.1","mono-3.0.10-windows","mono-3.0.11","mono-3.0.12","mono-3.0.2","mono-3.0.3","mono-3.0.4","mono-3.0.5","mono-3.0.6","mono-3.0.7","mono-3.2.3","mono-6.12.0.100","mono-6.12.0.101","mono-6.12.0.102","mono-6.12.0.103","mono-6.12.0.105","mono-6.12.0.106","mono-6.12.0.107","mono-6.12.0.109","mono-6.12.0.110","mono-6.12.0.111","mono-6.12.0.112","mono-6.12.0.113","mono-6.12.0.114","mono-6.12.0.86","mono-6.12.0.89","mono-6.12.0.90","mono-6.12.0.91","mono-6.12.0.93","mono-6.12.0.98","mono-6.12.0.99","monotouch-1-4","moon-1.9.0","moon-1.9.1","moon-1.9.2","moon-1.99.1","moon-1.99.2","moon-2.99.0.1","moon/2.99.0.4","moon/2.99.0.5","moon/2.99.0.6","moon/2.99.0.7","moon/2.99.0.8","moon/3.99.0.2","v2.1.24","v3.1.10","v3.1.11","v5.0.0","v5.0.1","v5.0.2"],"database_specific":{"vanir_signatures":[{"id":"CVE-2021-24112-a59c3744","deprecated":false,"target":{"file":"mono/metadata/w32process-unix.c","function":"ves_icall_System_Diagnostics_Process_ShellExecuteEx_internal"},"signature_type":"Function","source":"https://github.com/mono/mono/commit/c621c35ffa03273dbfb83055c7587c6a6617295a","signature_version":"v1","digest":{"function_hash":"332023839309420136721454079539944412274","length":2461}},{"id":"CVE-2021-24112-f1522214","deprecated":false,"target":{"file":"mono/metadata/w32process-unix.c"},"signature_type":"Line","source":"https://github.com/mono/mono/commit/c621c35ffa03273dbfb83055c7587c6a6617295a","signature_version":"v1","digest":{"line_hashes":["187426045632673110241050639906851923092","333043911263186902062214262369590588592","106389573904973060940279976284525218914","140061867908977381045271417549231451709","164227915027203989860172366370028994699","285677462648598166348343002929535890844","324916490189673593790121382141420535453","170179510509968663814232146624248700046","66152540540530829369605937576243742056","67575751260332271859057486015146050446","41292935628389076826433496871707273805","178483287709880595691649165559221994767","261188484371964551150085603238646450321","152321120229093870526445324093733590334"],"threshold":0.9}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24112.json","vanir_signatures_modified":"2026-04-11T13:53:57Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}