Microsoft Net Framework 4.8 vulnerabilities
35 known vulnerabilities affecting microsoft/microsoft_net_framework_4.8.
Total CVEs
35
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH27MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2023-36873HIGHCVSS 7.4≥ 4.8.0, < 4.8.4654.062023-08-08
CVE-2023-36873 [HIGH] CWE-20 .NET Framework Spoofing Vulnerability
.NET Framework Spoofing Vulnerability
.NET Framework Spoofing Vulnerability
cvelistv5
CVE-2023-24897HIGHCVSS 7.8≥ 4.8.0, < 4.8.4644.02023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2023-24936HIGHCVSS 7.5≥ 4.8.0, < 4.8.4644.02023-06-14
CVE-2023-24936 [HIGH] CVE-2023-24936: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2023-24895HIGHCVSS 7.8≥ 4.8.0, < 4.8.4644.02023-06-14
CVE-2023-24895 [HIGH] CVE-2023-24895: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2023-29331HIGHCVSS 7.5≥ 4.8.0, < 4.8.4644.02023-06-14
CVE-2023-29331 [HIGH] CWE-400 CVE-2023-29331: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
cvelistv5nvd
CVE-2023-32030HIGHCVSS 7.5≥ 4.8.0, < 4.8.4644.02023-06-14
CVE-2023-32030 [HIGH] CVE-2023-32030: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
cvelistv5nvd
CVE-2023-21808HIGHCVSS 7.8≥ 4.8.0, < 4.8.04614.052023-02-14
CVE-2023-21808 [HIGH] CWE-416 CVE-2023-21808: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2023-21722MEDIUMCVSS 5.0≥ 4.8.0, < 4.8.4614.082023-02-14
CVE-2023-21722 [MEDIUM] CWE-59 .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
cvelistv5
CVE-2022-41089HIGHCVSS 7.8≥ 4.8.0, < 04590.022022-12-13
CVE-2022-41089 [HIGH] CVE-2022-41089: .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-41064MEDIUMCVSS 5.8≥ 4.8.0, < 4.8.04584.082022-11-09
CVE-2022-41064 [MEDIUM] CVE-2022-41064: .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
cvelistv5nvd
CVE-2022-26832HIGHCVSS 7.5≥ 4.8.0, < 4.8.04494.032022-04-15
CVE-2022-26832 [HIGH] .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
cvelistv5
CVE-2022-21911HIGHCVSS 7.5≥ 4.8.0, < 4.8.4465.02022-01-11
CVE-2022-21911 [HIGH] .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
cvelistv5
CVE-2021-24111HIGHCVSS 7.5≥ 4.8.0, < publication2021-02-25
CVE-2021-24111 [HIGH] .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
cvelistv5
CVE-2020-16937MEDIUMCVSS 5.5≥ 4.8.0, < publication2020-10-16
CVE-2020-16937 [MEDIUM] CVE-2020-16937: <p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects
An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.
The update addresses the vulne
cvelistv5nvd
CVE-2020-1476MEDIUMCVSS 5.5≥ 4.8.0, < publication2020-08-17
CVE-2020-1476 [MEDIUM] CVE-2020-1476: An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files.
To exploit this vulnerability, an attacker would need to send a specially crafted request to an affected server.
The update
cvelistv5nvd
← Previous2 / 2