CVE-2021-24112CriticalCVSS 8.1

.NET Core Remote Code Execution Vulnerability

Published
February 9, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? When a .NET application utilizing libgdiplus on a non-Windows system accepts input, an attacker could send a specially crafted request that could result in remote code execution. Does this vulnerability affect applications running on Windows? No, Windows utilizes GDI+ to process these requests, and is not affected by this vulnerability.

🎯 Affected products5

  • .NET 5.0
  • .NET Core 2.1
  • .NET Core 3.1
  • Mono 6.12.0
  • Visual Studio 2019 for Mac

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (6)