cbcvebase.
CVE-2020-0605
published 2020-01-14

CVE-2020-0605: A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully…

PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
17.77%
96.8th percentile
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0606.

Affected

104 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_10_version_1607
microsoftmicrosoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_server_2016
microsoftmicrosoft_net_framework_3.5_and_4.7.1_4.7.2_on_windows_10_version_1709_for_32-bi
microsoftmicrosoft_net_framework_3.5_and_4.7.1_4.7.2_on_windows_10_version_1709_for_x64-b
microsoftmicrosoft_net_framework_3.5_and_4.7.2_on_windows_10_for_32-bit_systems
microsoftmicrosoft_net_framework_3.5_and_4.7.2_on_windows_10_for_x64-based_systems
microsoftmicrosoft_net_framework_3.5_and_4.7.2_on_windows_10_version_1803_for_32-bit_syst
microsoftmicrosoft_net_framework_3.5_and_4.7.2_on_windows_10_version_1803_for_x64-based_s
microsoftmicrosoft_net_framework_3.5_and_4.7.2_on_windows_10_version_1809_for_32-bit_syst
microsoftmicrosoft_net_framework_3.5_and_4.7.2_on_windows_10_version_1809_for_x64-based_s

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered when a user opens a specially crafted file that bypasses WPF XAML source markup validation in .NET Framework; monitor for unexpected XAML file opens or WPF application crashes.
  • The attack vector includes email delivery of a malicious file; monitor for email attachments opened by .NET/WPF applications, particularly XAML-related file types.
  • Red Hat describes this as a 'Bypass of WPF XAML payload prevention', indicating the crafted file likely contains a XAML payload; consider alerting on XAML files delivered via email or downloaded from the internet being opened by WPF processes.
  • ·No public exploit exists at time of advisory; Microsoft assessed exploitation as 'Less Likely' for both latest and older software releases.
  • ·Red Hat .NET Core packages (2.1, 2.2, 3.0, 3.1) and RHEL 8 dotnet packages are all confirmed not affected; the vulnerable components are Windows-specific WPF/.NET Framework components not shipped by Red Hat.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
ghsa8.8HIGH
osv8.8HIGH
vendor_msrc8.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.