Remote Code Execution Vulnerability in .NET Software by Microsoft
CVE-2020-0606
8.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 14 January 2020
Badges
👾 Exploit Exists🟣 EPSS 39%
Summary
A remote code execution vulnerability exists in .NET software, allowing attackers to execute arbitrary code under the context of the current user. This occurs when the software improperly checks the source markup of certain files. If successfully exploited, an attacker could gain the same privileges as the user, potentially leading to unauthorized access and control over the affected system.
Affected Version(s)
.NET Core 3.0
.NET Core 3.1
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
References
EPSS Score
39% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved