PT-2020-1326 · Microsoft · .Net Framework+1

Published

2020-01-14

·

Updated

2022-05-24

·

CVE-2020-0606

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions .NET Framework (affected versions not specified) .NET Core (affected versions not specified)
Description A remote code execution issue exists due to insufficient input validation. An attacker could exploit this to run arbitrary code in the context of the current user. If the user has administrative rights, the attacker could take control of the system, install programs, view, change or delete data, or create new accounts with full rights. Exploitation requires a user to open a specially crafted file with an affected version of .NET Framework.
Recommendations For .NET Framework, update to a version that includes the fix for this issue. For .NET Core, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of .NET Framework and .NET Core until a patch is available. Avoid opening specially crafted files with affected versions of .NET Framework to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00228
CVE-2020-0606
GHSA-R4MW-GXF7-VXR9

Affected Products

.Net Framework
Net Core