Remote Code Execution Vulnerability in ASP.NET Core by Microsoft
CVE-2020-0603

8.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 January 2020

Summary

A vulnerability exists in ASP.NET Core due to improper handling of objects in memory. An attacker can exploit this issue to execute arbitrary code under the privileges of the current user, potentially leading to unauthorized access and data manipulation. Organizations using affected versions should review security updates and apply necessary patches to mitigate risks associated with this vulnerability.

Affected Version(s)

ASP.NET Core 2.1

ASP.NET Core 3.0

ASP.NET Core 3.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.