CVE-2020-1046: .NET Framework Remote Code Execution Vulnerability
A remote code execution vulnerability exists when Microsoft .NET Framework processes input, aka '.NET Framework Remote Code Execution Vulnerability'.
Other sources
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application. The security update addresses the vulnerability by correcting how .NET Framework processes input.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-1046?
CVE-2020-1046 is a remote code execution vulnerability in Microsoft .NET Framework when processing input.
How severe is CVE-2020-1046?
CVE-2020-1046 has a severity rating of 7.8 (critical).
Which software is affected by CVE-2020-1046?
CVE-2020-1046 affects Microsoft .NET Framework versions 2.0 SP2, 3.5, and 4.7.2.
How can I fix CVE-2020-1046?
To fix CVE-2020-1046, update the affected versions of Microsoft .NET Framework to the latest available patch.
Where can I find more information about CVE-2020-1046?
You can find more information about CVE-2020-1046 on the Microsoft Security Guidance Advisory page: [link](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1046)