cbcvebase.
CVE-2020-1066
published 2020-05-21

CVE-2020-1066: An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability…

PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
2.31%
81.4th percentile
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.0
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftmicrosoft_net_framework_3.5.1
microsoftnet_framework
microsoftnet_framework
msrcmicrosoft_net_framework_3.0_service_pack_2_on_windows_server_2008_for_32-bit_sy
msrcmicrosoft_net_framework_3.0_service_pack_2_on_windows_server_2008_for_x64-based
msrcmicrosoft_net_framework_3.5.1_on_windows_7_for_32-bit_systems_service_pack_1
msrcmicrosoft_net_framework_3.5.1_on_windows_7_for_x64-based_systems_service_pack_1
msrcmicrosoft_net_framework_3.5.1_on_windows_server_2008_r2_for_x64-based_systems_s

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires local machine access followed by execution of a malicious program — monitor for suspicious local process execution by lower-privileged users, particularly processes that invoke COM object activation via .NET Framework.
  • The vulnerability lies specifically in how .NET Framework activates COM objects — focus detection on anomalous COM activation events (e.g., unusual CLSID instantiation) originating from .NET Framework processes running under low-privilege accounts.
  • ·.NET Core is NOT affected — only the full .NET Framework is vulnerable. Red Hat packages rh-dotnet21-dotnet, rh-dotnet31-dotnet, dotnet, and dotnet31 are all confirmed not affected.
  • ·As of the advisory publication, the vulnerability had not been publicly disclosed or exploited in the wild, and exploitation was rated 'Less Likely' for both latest and older software releases.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.