CVE-2020-16937
published 2020-10-16CVE-2020-16937: An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
3.29%
87.1th percentile
An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.
The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_2.0_service_pack_2 | >= 2.0.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5 | >= 3.5.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5.1 | >= 3.5.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | >= 3.0.0.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5_and_4.6_4.6.1_4.6.2 | >= 3.5.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5_and_4.7.1_4.7.2 | >= 3.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < publication | publication |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < publication | publication |
| microsoft | microsoft_net_framework_4.5.2 | >= 4.0.0.0 < publication | publication |
| microsoft | microsoft_net_framework_4.6 | >= 4.0.0.0 < publication | publication |
| microsoft | microsoft_net_framework_4.6_4.6.1_4.6.2_4.7_4.7.1_4.7.2 | >= 4.0.0.0 < publication | publication |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < publication | publication |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| msrc | microsoft_net_framework_2.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.5 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rc5w-jj6x-53wj: An information disclosure vulnerability exists when the
ghsa_unreviewed·2022-05-24
CVE-2020-16937 [MEDIUM] CWE-200 GHSA-rc5w-jj6x-53wj: An information disclosure vulnerability exists when the
An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory, aka '.NET Framework Information Disclosure Vulnerability'.
Red Hat
dotnet: .NET Framework improperly handles objects in memory which could result in Information Disclosure
vendor_redhat·2020-10-21·CVSS 4.7
CVE-2020-16937 [MEDIUM] CWE-200 dotnet: .NET Framework improperly handles objects in memory which could result in Information Disclosure
dotnet: .NET Framework improperly handles objects in memory which could result in Information Disclosure
An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.
The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet31 (.NET Core 3.1 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet3.1 (Red Hat Enterprise
Microsoft
.NET Framework Information Disclosure Vulnerability
vendor_msrc·2020-10-13·CVSS 4.7
CVE-2020-16937 [MEDIUM] .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.
The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-16
Published