CVE-2020-0606: Input Validation
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-0606?
CVE-2020-0606 is a remote code execution vulnerability in .NET software.
How does CVE-2020-0606 impact the system?
CVE-2020-0606 can allow an attacker to run arbitrary code in the context of the current user.
What is the severity of CVE-2020-0606?
CVE-2020-0606 has a severity rating of 8.8, which is considered critical.
Which software versions are affected by CVE-2020-0606?
CVE-2020-0606 affects Microsoft .NET Framework versions 3.0 SP2, 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and .NET Core versions 3.0, 3.1.
How can CVE-2020-0606 be fixed?
To fix CVE-2020-0606, it is recommended to apply the necessary security updates provided by Microsoft.