Skip to content
COOEY

EXPOSURES › CVE-2020-0646

CVE-2020-0646

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-0646 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Microsoft .NET Framework remote code execution vulnerability allows attackers to execute arbitrary code on vulnerable systems.

This vulnerability stems from improper input validation in the .NET Framework, enabling remote code execution without requiring user interaction. DIB organizations must ensure all .NET Framework components are patched immediately, as unpatched instances are actively exploited in the wild and can lead to full system compromise, data exfiltration, or lateral movement within networks.

Shame score — A known RCE vulnerability in a widely deployed framework that remains unpatched and actively exploited in the wild, representing a severe negligence in patch management and system hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Microsoft faced severe fallout for a critical RCE vulnerability in .NET Framework, though the provided sources lack direct press coverage or authoritative commentary on the event's reception, relying
cooey ↗ severe-fallout -0.60
Technical acknowledgment of a critical flaw without public praise or condemnation in the provided text.
"Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution."
app.opencve.io ↗ severe-fallout +0.00
Irrelevant source listing CVEs without specific commentary on CVE-2020-0646.
NVD ↗ severe-fallout +0.00
Irrelevant source showing NVD page without specific commentary on CVE-2020-0646.
www.cvefind.com ↗ severe-fallout +0.00
Irrelevant source showing CVE database without specific commentary on CVE-2020-0646.
senserva.com ↗ severe-fallout +0.00
Irrelevant source showing Microsoft Patch Tuesday without specific commentary on CVE-2020-0646.
support.apple.com ↗ severe-fallout +0.00
Irrelevant source showing Apple security releases without specific commentary on CVE-2020-0646.
www.pcworld.com ↗ severe-fallout +0.00
Irrelevant source showing Microsoft Wi-Fi warnings without specific commentary on CVE-2020-0646.
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized