Remote code execution in Microsoft.WindowsDesktop.App.Ref
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Package
Affected versions
= 3.0.1
= 3.1.0
Patched versions
3.0.2
3.1.1
>= 3.0.0, < 3.0.2
>= 3.1.0, < 3.1.11
3.0.2
3.1.11
>= 3.0.0, < 3.0.2
>= 3.1.0, < 3.1.11
3.0.2
3.1.11
Description
Published by the National Vulnerability Database
Jan 14, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 28, 2022
Last updated
Jan 30, 2023
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.
References