First published: Thu Feb 25 2021(Updated: )
.NET Core Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/System.Text.Encodings.Web | =5.0.0 | 5.0.1 |
nuget/System.Text.Encodings.Web | >=4.6.0<4.7.2 | 4.7.2 |
nuget/System.Text.Encodings.Web | >=4.0.0<4.5.1 | 4.5.1 |
Microsoft .NET Framework | >=5.0<5.0.4 | |
Microsoft .NET Core SDK | >=2.1<2.1.28 | |
Microsoft .NET Core SDK | >=3.1<3.1.15 | |
PowerShell Core | =7.0 | |
PowerShell Core | =7.1 | |
Visual Studio Professional 2019 | >=16.0<=16.9 | |
Microsoft Visual Studio 2019 for Mac | ||
Fedora | =32 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
.NET Core Remote Code Execution Vulnerability that is unique from CVE-2021-24112.
It affects Microsoft .NET versions 5.0.4 and earlier, Microsoft .NET Core versions 2.1.28 and earlier, Microsoft PowerShell Core versions 7.0 and 7.1, and Microsoft Visual Studio 2019 versions 16.0 to 16.9.
It has a severity rating of 9.8 (Critical).
Apply the necessary security updates provided by Microsoft and follow their recommendations.
You can find more information about this vulnerability at the following references: [Reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S2AZOUKMCHT2WBHR7MYDTYXWOBHZW5P5/), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TW3ZSJTTMZAFKGW7NJWTVVFZUYYU2SJZ/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBOSSX7U6BSHV5RI74FCOW4ITJ5RRJR5/)