EXPOSURES › CVE-2020-0646
CVE-2020-0646
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft .NET Framework remote code execution vulnerability allows attackers to execute arbitrary code on vulnerable systems.
This vulnerability stems from improper input validation in the .NET Framework, enabling remote code execution without requiring user interaction. DIB organizations must ensure all .NET Framework components are patched immediately, as unpatched instances are actively exploited in the wild and can lead to full system compromise, data exfiltration, or lateral movement within networks.
Shame score — A known RCE vulnerability in a widely deployed framework that remains unpatched and actively exploited in the wild, representing a severe negligence in patch management and system hardening.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.
"Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |