cbcvebase.
CVE-2020-0603
published 2020-01-14

CVE-2020-0603: A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully…

PriorityP261high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
19.83%
97.1th percentile
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.

Affected

17 ranges
VendorProductVersion rangeFixed in
microsoftasp.net_core
microsoftasp.net_core
microsoftasp.net_core
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.linux-arm64>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-arm64>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.linux-musl-x64>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.linux-x64>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.osx-x64>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.win-arm>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.win-x64>= 3.1.0 < 3.1.13.1.1
microsoftmicrosoft.aspnetcore.app.runtime.win-x86>= 3.1.0 < 3.1.13.1.1
msrcasp.net_core_2.1
msrcasp.net_core_3.0
msrcasp.net_core_3.1
redhatenterprise_linux
redhatenterprise_linux_eus

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via specially crafted HTTP requests to an ASP.NET Core application using SignalR; monitor for anomalous or malformed SignalR connection/disconnection traffic
  • The vulnerability is specifically triggered by client-deleted/dropped connections in ASP.NET Core SignalR; monitor for patterns of rapid connection teardowns or abrupt disconnections to SignalR endpoints
  • The root cause is a write-to-freed-memory (use-after-free/memory corruption) condition on the server side; look for ASP.NET Core process crashes, unexpected restarts, or memory corruption indicators in application logs
  • No authentication is required to exploit this vulnerability; any unauthenticated external client can attempt exploitation against exposed ASP.NET Core SignalR endpoints
  • ·Red Hat packages rh-dotnet21, rh-dotnet22, dotnet (RHEL8), and dotnet3.1 (RHEL8) are confirmed NOT affected; focus detection efforts on .NET Core 3.0 and earlier affected upstream releases
  • ·Microsoft assessed exploitation as 'Less Likely' for both latest and older software releases, and confirmed no public exploit or in-the-wild exploitation at time of disclosure

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.