CVE-2020-0605 is a vulnerability in Microsoft .NET Core
Published on January 14, 2020
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0606.
Products Associated with CVE-2020-0605
Want to know whenever a new CVE is published for Microsoft .NET Core? stack.watch will email you.
Affected Versions
Microsoft .NET Core:- Version 3.0 is affected.
- Version 3.1 is affected.
- Version Windows RT 8.1 is affected.
- Version Windows 8.1 for x64-based systems is affected.
- Version Windows 7 for 32-bit Systems Service Pack 1 is affected.
- Version Windows 8.1 for 32-bit systems is affected.
- Version Windows 7 for x64-based Systems Service Pack 1 is affected.
- Version Windows Server 2012 R2 is affected.
- Version Windows Server 2012 (Server Core installation) is affected.
- Version Windows Server 2012 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) is affected.
- Version Windows Server 2012 R2 (Server Core installation) is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 is affected.
- Version Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2 is affected.
- Version Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version Windows 10 Version 1607 for 32-bit Systems is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version 1903 is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version Windows 8.1 for x64-based systems is affected.
- Version Windows RT 8.1 is affected.
- Version Windows 8.1 for 32-bit systems is affected.
- Version Windows Server 2008 for 32-bit Systems Service Pack 2 is affected.
- Version Windows 7 for x64-based Systems Service Pack 1 is affected.
- Version Windows 7 for 32-bit Systems Service Pack 1 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 is affected.
- Version Windows Server 2012 (Server Core installation) is affected.
- Version Windows Server 2012 R2 (Server Core installation) is affected.
- Version Windows Server 2012 is affected.
- Version Windows Server 2008 for x64-based Systems Service Pack 2 is affected.
- Version Windows Server 2012 R2 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) is affected.
- Version Windows 7 for x64-based Systems Service Pack 1 is affected.
- Version Windows 7 for 32-bit Systems Service Pack 1 is affected.
- Version Windows Server 2008 R2 for x64-based Systems Service Pack 1 is affected.
- Version Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 is affected.
- Version Windows 8.1 for x64-based systems is affected.
- Version Windows Server 2012 R2 (Server Core installation) is affected.
- Version Windows Server 2012 is affected.
- Version Windows Server 2012 (Server Core installation) is affected.
- Version Windows 8.1 for 32-bit systems is affected.
- Version Windows Server 2012 R2 is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
- Version unspecified is affected.
Vulnerable Packages
The following package name and versions may be associated with CVE-2020-0605
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| nuget | PowerShell | < 7.0.0 | 7.0.0 |
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.