CVE-2020-1046Microsoft NET Framework 2.0 Service Pack 2 vulnerability

5 documents5 sources
Severity
7.8HIGHNVD
EPSS
11.3%
top 6.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 24

Description

A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application. The security update addresses the vulnerability by correcting how .NET Framework processes input.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5microsoft/microsoft_net_framework_3.53.5.0publication
CVEListV5microsoft/microsoft_net_framework_3.5.13.5.0publication
CVEListV5microsoft/microsoft_net_framework_3.5_and_4.84.8.0publication
CVEListV5microsoft/microsoft_net_framework_3.5_and_4.7.24.7.0publication

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p734-hj82-4cvx: A remote code execution vulnerability exists when Microsoft2022-05-24
CVEList
.NET Framework Remote Code Execution Vulnerability2020-08-17

📋Vendor Advisories

1
Microsoft
.NET Framework Remote Code Execution Vulnerability2020-08-11

💬Community

1
Bugzilla
CVE-2020-6104 f2fs-tools: specially crafted f2fs filesystem can cause information disclosure2020-10-15
CVE-2020-1046 — Microsoft vulnerability | cvebase