7.8
CVE-2020-1066
- EPSS 2.45%
- Veröffentlicht 21.05.2020 23:15:12
- Zuletzt bearbeitet 19.08.2026 17:17:12
- Erkennungen
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Framework Version 3.0 Update sp2
Microsoft ≫ .Net Framework Version 3.5.1
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.45% | 0.831 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1066
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1066