A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dotnet-apphost-pack-3.0Upgrade aspnetcore-targeting-pack-3.0Upgrade dotnet-sdk-3.0Upgrade dotnet-hostfxr-3.0Upgrade dotnet3.0-debuginfoUpgrade dotnet-host-debuginfoUpgrade dotnet-apphost-pack-3.0-debuginfoUpgrade dotnet-hostfxr-3.0-debuginfoUpgrade dotnetUpgrade dotnet-hostUpgrade dotnet-sdk-3.0-debuginfoUpgrade dotnet-runtime-3.0-debuginfoUpgrade aspnetcore-runtime-3.0Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-templates-3.0Upgrade dotnet-runtime-3.0Upgrade dotnet3.0-debugsourceUpgrade dotnet-targeting-pack-3.0 | Jan 17, 2020 | Jan 14, 2020 |
| Oracle_linux | — | Upgrade dotnet-targeting-pack-3.0Upgrade dotnet-hostfxr-3.0Upgrade aspnetcore-runtime-3.0Upgrade dotnetUpgrade dotnet-apphost-pack-3.0Upgrade aspnetcore-targeting-pack-3.0Upgrade dotnet-hostUpgrade dotnet-sdk-3.0Upgrade dotnet-templates-3.0Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-runtime-3.0 | Jan 21, 2020 | Jan 14, 2020 |
| Redhat_linux | — | Upgrade dotnetUpgrade netstandard-targeting-pack-2.1Upgrade dotnet3.0-debugsourceUpgrade aspnetcore-runtime-3.0Upgrade dotnet-targeting-pack-3.0Upgrade dotnet-hostfxr-3.0-debuginfoUpgrade dotnet-sdk-3.0Upgrade dotnet-sdk-3.0-debuginfoUpgrade aspnetcore-targeting-pack-3.0Upgrade dotnet-apphost-pack-3.0-debuginfoUpgrade dotnet-hostfxr-3.0Upgrade dotnet-templates-3.0Upgrade dotnet-runtime-3.0Upgrade dotnet-hostUpgrade dotnet-apphost-pack-3.0Upgrade dotnet-host-debuginfoUpgrade dotnet3.0-debuginfoUpgrade dotnet-runtime-3.0-debuginfo | Jan 17, 2020 | Jan 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub