CVE-2020-1066
published 2020-05-21CVE-2020-1066: An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability…
PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
2.31%
81.4th percentile
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| msrc | microsoft_net_framework_3.0_service_pack_2_on_windows_server_2008_for_32-bit_sy | — | — |
| msrc | microsoft_net_framework_3.0_service_pack_2_on_windows_server_2008_for_x64-based | — | — |
| msrc | microsoft_net_framework_3.5.1_on_windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | microsoft_net_framework_3.5.1_on_windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | microsoft_net_framework_3.5.1_on_windows_server_2008_r2_for_x64-based_systems_s | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation requires local machine access followed by execution of a malicious program — monitor for suspicious local process execution by lower-privileged users, particularly processes that invoke COM object activation via .NET Framework. ↗
- →The vulnerability lies specifically in how .NET Framework activates COM objects — focus detection on anomalous COM activation events (e.g., unusual CLSID instantiation) originating from .NET Framework processes running under low-privilege accounts. ↗
- ·.NET Core is NOT affected — only the full .NET Framework is vulnerable. Red Hat packages rh-dotnet21-dotnet, rh-dotnet31-dotnet, dotnet, and dotnet31 are all confirmed not affected. ↗
- ·As of the advisory publication, the vulnerability had not been publicly disclosed or exploited in the wild, and exploitation was rated 'Less Likely' for both latest and older software releases. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jp98-j3r8-w99v: An elevation of privilege vulnerability exists in
ghsa_unreviewed·2022-05-24
CVE-2020-1066 [HIGH] CWE-269 GHSA-jp98-j3r8-w99v: An elevation of privilege vulnerability exists in
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.
VulnCheck
.NET Framework Elevation of Privilege Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-1066 [HIGH] .NET Framework Elevation of Privilege Vulnerability
.NET Framework Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.
Affected: Microsoft .NET Framework
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.acronis.com/en/tru/posts/makop-ransomware-guloader-and-privilege-escalatio
Red Hat
NET: local elevation of privilege
vendor_redhat·2020-05-12·CVSS 7.8
CVE-2020-1066 [HIGH] CWE-250 NET: local elevation of privilege
NET: local elevation of privilege
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.
Statement: This only affects the .NET Framework and not .NET Core.
Package: rh-dotnet21-dotnet (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet31-dotnet (.NET Core 3.1 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet31 (Red Hat Enterprise Linux 8) - Not af
Microsoft
.NET Framework Elevation of Privilege Vulnerability
vendor_msrc·2020-05-12·CVSS 7.8
CVE-2020-1066 [HIGH] .NET Framework Elevation of Privilege Vulnerability
.NET Framework Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.
To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.
The update addresses the vulnerability by correcting how .NET Framework activates COM objects.
.NET Framework: .NET Framework
Issuing CNA: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4552939
Reference: https://catalog.update.microsoft.com/v7/site/Searc
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1066 .NET: local elevation of privilege
bugzilla·2020-06-29·CVSS 7.8
CVE-2020-1066 [HIGH] CVE-2020-1066 .NET: local elevation of privilege
CVE-2020-1066 .NET: local elevation of privilege
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.
References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1066
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1066
---
Statement:
This only affects the .NET Framework and not .NET Core.
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901 , a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provi
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
CVE-2020-0901 [CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901, a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the full Snort rule
2020-05-21
Published
Exploited in the wild