Input validation error in Microsoft .NET Framework and Microsoft .NET Core - CVE-2020-0605

 

Input validation error in Microsoft .NET Framework and Microsoft .NET Core - CVE-2020-0605

Published: January 14, 2020


Vulnerability identifier: #VU24269
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0605
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input when the software fails to check the source markup of a file. A remote attacker can trick a victim to open s specially crafted file and execute arbitrary code in the context of the current user.


Affected software

Microsoft .NET Framework
Microsoft .NET Core
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax

How to mitigate CVE-2020-0605

Install update from vendor's website.

Solutions Enabler Virtual Appliance - addressed in versions 9.0.0.19, 9.1.0.6
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17

External References

Related Security Bulletins