.NET Framework Remote Code Execution Vulnerability for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 8.1 and Server 2012 R2 for x64 (KB4532970)
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.865%
CVE Information
Patch Details
Patch associated with this vulnerability is supported by ManageEngine.
Patch ID
28176
Patch Description
KB4534978, 2020-01 Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 8.1 and Server 2012 R2 for x64 (KB4532970)
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0605
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0646
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0606
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0606
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0646
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0605