A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dotnet-runtime-3.0Upgrade dotnet-templates-3.0Upgrade dotnet3.0-debugsourceUpgrade netstandard-targeting-pack-2.1Upgrade dotnet-targeting-pack-3.0Upgrade dotnet-hostUpgrade aspnetcore-targeting-pack-3.0Upgrade dotnet-apphost-pack-3.0Upgrade dotnet-runtime-3.0-debuginfoUpgrade dotnet-host-debuginfoUpgrade dotnet-hostfxr-3.0Upgrade dotnet3.0-debuginfoUpgrade dotnet-sdk-3.0-debuginfoUpgrade dotnet-sdk-3.0Upgrade dotnet-hostfxr-3.0-debuginfoUpgrade aspnetcore-runtime-3.0Upgrade dotnetUpgrade dotnet-apphost-pack-3.0-debuginfo | Jan 17, 2020 | Jan 14, 2020 |
| Oracle_linux | — | Upgrade aspnetcore-runtime-3.0Upgrade aspnetcore-targeting-pack-3.0Upgrade dotnet-apphost-pack-3.0Upgrade dotnet-targeting-pack-3.0Upgrade dotnetUpgrade dotnet-hostfxr-3.0Upgrade dotnet-hostUpgrade dotnet-runtime-3.0Upgrade dotnet-templates-3.0Upgrade dotnet-sdk-3.0Upgrade netstandard-targeting-pack-2.1 | Jan 21, 2020 | Jan 14, 2020 |
| Redhat_linux | — | Upgrade dotnet-sdk-3.0Upgrade dotnet-hostfxr-3.0-debuginfoUpgrade dotnetUpgrade aspnetcore-runtime-3.0Upgrade dotnet-targeting-pack-3.0Upgrade netstandard-targeting-pack-2.1Upgrade dotnet3.0-debugsourceUpgrade dotnet-runtime-3.0-debuginfoUpgrade dotnet-hostUpgrade dotnet-sdk-3.0-debuginfoUpgrade dotnet-apphost-pack-3.0-debuginfoUpgrade dotnet-host-debuginfoUpgrade dotnet-apphost-pack-3.0Upgrade dotnet-hostfxr-3.0Upgrade dotnet-runtime-3.0Upgrade aspnetcore-targeting-pack-3.0Upgrade dotnet-templates-3.0Upgrade dotnet3.0-debuginfo | Jan 17, 2020 | Jan 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub