CVE-2020-16937
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD (Secondary)
Description
<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p>
<p>To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.</p>
<p>The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.</p>
Affected (11)
Products: Microsoft: .net Framework
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 sp2 |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1809 |
Microsoft Windows Server 2016 | Version 1903 |
Microsoft Windows Server 2019 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.5.2 |
Configuration J
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6.1 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1607 |
Microsoft Windows 7 | All versions |
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Server 2012 | All versions |
Microsoft Windows Server 2016 | All versions |
References (2)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.