Input validation error in Microsoft .NET Framework and Microsoft .NET Core - CVE-2020-0606
Published: January 14, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when the software fails to check the source markup of a file. A remote attacker can trick a victim to open s specially crafted file and execute arbitrary code in the context of the current user.
Affected software
Microsoft .NET Core
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2020-0606
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17