CVE-2020-0603
published 2020-01-14CVE-2020-0603: A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully…
PriorityP261high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
19.83%
97.1th percentile
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| msrc | asp.net_core_2.1 | — | — |
| msrc | asp.net_core_3.0 | — | — |
| msrc | asp.net_core_3.1 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via specially crafted HTTP requests to an ASP.NET Core application using SignalR; monitor for anomalous or malformed SignalR connection/disconnection traffic ↗
- →The vulnerability is specifically triggered by client-deleted/dropped connections in ASP.NET Core SignalR; monitor for patterns of rapid connection teardowns or abrupt disconnections to SignalR endpoints ↗
- →The root cause is a write-to-freed-memory (use-after-free/memory corruption) condition on the server side; look for ASP.NET Core process crashes, unexpected restarts, or memory corruption indicators in application logs ↗
- →No authentication is required to exploit this vulnerability; any unauthenticated external client can attempt exploitation against exposed ASP.NET Core SignalR endpoints ↗
- ·Red Hat packages rh-dotnet21, rh-dotnet22, dotnet (RHEL8), and dotnet3.1 (RHEL8) are confirmed NOT affected; focus detection efforts on .NET Core 3.0 and earlier affected upstream releases ↗
- ·Microsoft assessed exploitation as 'Less Likely' for both latest and older software releases, and confirmed no public exploit or in-the-wild exploitation at time of disclosure ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Remote code execution in ASP.NET Core
osv·2022-05-24
CVE-2020-0603 [HIGH] Remote code execution in ASP.NET Core
Remote code execution in ASP.NET Core
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
GHSA
Remote code execution in ASP.NET Core
ghsa·2022-05-24
CVE-2020-0603 [HIGH] CWE-119 Remote code execution in ASP.NET Core
Remote code execution in ASP.NET Core
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
Red Hat
dotnet: Memory Corruption in SignalR
vendor_redhat·2020-01-14·CVSS 8.8
CVE-2020-0603 [HIGH] CWE-119 dotnet: Memory Corruption in SignalR
dotnet: Memory Corruption in SignalR
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
A memory corruption flaw was found in ASP.NET core. A client can write to freed memory on the server which could result in undefined behavior. An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary code by sending specially crafted requests to an ASP.NET Core application.
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet22 (.NET Core 2.2 on Red Hat Enterprise Linux) - Not affe
Microsoft
ASP.NET Core Remote Code Execution Vulnerability
vendor_msrc·2020-01-14·CVSS 8.8
CVE-2020-0603 [HIGH] ASP.NET Core Remote Code Execution Vulnerability
ASP.NET Core Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle client deleted connections.
An attacker who successfully exploited the vulnerability could run arbitrary code in memory on the server. Exploitation of the vulnerability requires that a user perform certain actions during the connection process.
The security update addresses the vulnerability by correcting how ASP.NET Core handles deleted connections.
ASP.NET: ASP.NET
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://dotnet.microsoft.com/download/dotn
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-01-14·CVSS 8.1
CVE-2020-0601 [HIGH] Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw. Updated January 15th: Added an Advanced Custom Detection (ACD) signature for AMP that can be used to detect exploitation of CVE-2020-0601 by spoofing certificates masquerading as a Microsoft ECC Code Signing Certificate Authority.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 49 vulnerabilities, eight of which are considered critical.
This month's security update is particularly important for its disclosure of two vulnerabilities related to a core cryptographic component in all versions of Windows. CVE-2020-0601 could allow an attacker to use cryptography
Tenable
Microsoft’s January 2020 Patch Tuesday Kicks Off the New Year with 49 New CVEs
blogs_tenable·2020-01-14
Microsoft’s January 2020 Patch Tuesday Kicks Off the New Year with 49 New CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-01-14·CVSS 8.1
CVE-2020-0601 [HIGH] Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Updated January 15th: Added an Advanced Custom Detection (ACD) signature for AMP that can be used to detect exploitation of CVE-2020-0601 by spoofing certificates masquerading as a Microsoft ECC Code Signing Certificate Authority.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 49 vulnerabilities, eight of which are considered critical.
This month's security update is particularly important for its disclosure of two vulnerabilities related to a core cryptographic component in all versions of Windows. CVE-2020-0601 could allow an attacker to use cryptography to sign a malicious executable, making the file appear as if it was from a trusted sou
Bugzilla
CVE-2020-0603 dotnet: Memory Corruption in SignalR
bugzilla·2020-01-09·CVSS 8.8
CVE-2020-0603 [HIGH] CVE-2020-0603 dotnet: Memory Corruption in SignalR
CVE-2020-0603 dotnet: Memory Corruption in SignalR
A vulnerability related to handling objects in memory has been reported in ASP.NET Core. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code by sending specially crafted requests to an ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
https://github.com/aspnet/Announcements/issues/403
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:0130 https://access.redhat.com/errata/RHSA-2020:0130
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:0134 https://access.redhat.com/errata/RHSA-2020:013
https://access.redhat.com/errata/RHSA-2020:0130https://access.redhat.com/errata/RHSA-2020:0134https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603https://access.redhat.com/errata/RHSA-2020:0130https://access.redhat.com/errata/RHSA-2020:0134https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
2020-01-14
Published