CVE-2020-0646
CRITICAL(9.8)KEVWahrscheinlich ausgenutzt
Microsoft .NET Framework Remote Code Execution Vulnerability
Beschreibung
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenCWEs
Betroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| microsoft | .net framework | 3.0; 3.5; 4.6.2; 4.7; 4.7.1; 4.7.2; 4.8; 3.5.1; 4.5.2; 4.6; 4.6.1 |
Mehrere CVSS-Bewertungen
Quelle: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Referenzen
- http://packetstormsecurity.com/files/156930/SharePoint-Workflows-XOML-Injection.html(Exploit, Third Party Advisory, VDB Entry)
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0646(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.