← Back

CVE-2020-1066

nvd nist
Published: May 21, 2020Modified: Aug 19, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects.

Affected (2)

1 product
.net Framework
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.0 sp2
Running on/withPlatform Versions
Microsoft
Windows Server 2008
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 3.5.1
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2008
Version r2 sp1

References (2)

Timeline

No history available yet.