CVE-2020-1046
HIGH.NET Framework - Remote Code Execution via File Upload
Title source: llmDescription
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application. The security update addresses the vulnerability by correcting how .NET Framework processes input.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1046
Scores
CVSS v3
7.8
EPSS
0.0376
EPSS Percentile
88.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
Status
published
Products (4)
microsoft/.net_framework
2.0 sp2
microsoft/.net_framework
3.5
microsoft/.net_framework
4.7.2
microsoft/.net_framework
3.5.1
Published
Aug 17, 2020
Tracked Since
Feb 18, 2026