.NET Framework Remote Code Execution Vulnerability for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 8.1 and Server 2012 R2 for x64 (KB4532970)

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.865%

CVE Information

Patch Details

Patch associated with this vulnerability is supported by ManageEngine.

Patch ID
28176

Patch Description
KB4534978, 2020-01 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 8.1 and Server 2012 R2 for x64 (KB4532970)

References

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0605
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0646
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0606
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0606
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0646
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0605