CVE-2020-0603Critical
ASP.NET Core Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle client deleted connections. An attacker who successfully exploited the vulnerability could run arbitrary code in memory on the server. Exploitation of the vulnerability requires that a user perform certain actions during the connection process. The security update addresses the vulnerability by correcting how ASP.NET Core handles deleted connections.
🎯 Affected products3
- ASP.NET Core 2.1
- ASP.NET Core 3.0
- ASP.NET Core 3.1
✅ Remediation
KBRelease Notes (Security Update)