FAIL › dossier
.NET Framework
PRODUCT· dossier confidence 20%
Microsoft's .NET Framework has a history of critical security vulnerabilities, including remote code execution flaws, requiring frequent security updates and raising concerns about the platform's overall security posture. Recent updates, like KB5104032 and KB5100998, address multiple CVEs, highlighting the ongoing need for vigilance. The platform's widespread use in DIB applications necessitates careful management and patching.
The .NET Framework has a history of significant security vulnerabilities, including multiple remote code execution (RCE) flaws. Microsoft regularly releases security updates to address these vulnerabilities, but the frequency of high-severity issues suggests ongoing challenges in secure development practices.
- CVE-2024-29059 (RCE)
- CVE-2017-8759 (RCE)
- CVE-2020-0646 (RCE)
- CVE-2026-47304 (Cryptographic Signature Verification)
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2017-8759 | high | Microsoft .NET Framework RCE vulnerability (CVE-2017-8759) was actively exploited in the wild, allowing attackers to take full control of systems. |
| 2021-11-03 | CVE-2020-0646 | high | Microsoft .NET Framework remote code execution vulnerability allows attackers to execute arbitrary code on vulnerable systems. |
| 2025-02-04 | CVE-2024-29059 | high | A Microsoft .NET Framework vulnerability allows attackers to expose sensitive information and potentially execute code remotely, currently being exploited in the wild. |
| 2026-07-14 | CVE-2026-47304 | high | CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized |
- KB5104032: .NET 8.0.29 July 2026 Security Update — What It Fixes and ... · sigmawire.net
- KB5100998: What It Is, What It Fixes, Issues Reported and How to Install · sigmawire.net
- KB5097149 - Details, Issues, & Feedback - NinjaOne · www.ninjaone.com