Remote Code Execution Vulnerability in .NET Software by Microsoft
CVE-2020-0606
8.8HIGH
Summary
A remote code execution vulnerability exists in .NET software, allowing attackers to execute arbitrary code under the context of the current user. This occurs when the software improperly checks the source markup of certain files. If successfully exploited, an attacker could gain the same privileges as the user, potentially leading to unauthorized access and control over the affected system.
Affected Version(s)
.NET Core 3.0
.NET Core 3.1
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved