Remote Code Execution Vulnerability in .NET Framework by Microsoft
CVE-2020-0605

8.8HIGH

Summary

A remote code execution vulnerability exists in the .NET Framework due to improper verification of source markup in files. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of the current user. This could potentially allow the attacker to take control of affected systems and gain unauthorized access to sensitive information.

Affected Version(s)

.NET Core 3.0

.NET Core 3.1

Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.