Security Updates for Microsoft .NET Framework (May 2020)

high Nessus Plugin ID 136564

Synopsis

The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.

Description

The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. (CVE-2020-1108)

- An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. (CVE-2020-1066)

Solution

Microsoft has released security updates for Microsoft .NET Framework.

See Also

https://support.microsoft.com/en-us/help/4556406/kb4556406

https://support.microsoft.com/en-us/help/4556405/kb4556405

https://support.microsoft.com/en-us/help/4556404/kb4556404

https://support.microsoft.com/en-us/help/4556403/kb4556403

https://support.microsoft.com/en-us/help/4556402/kb4556402

https://support.microsoft.com/en-us/help/4556401/kb4556401

https://support.microsoft.com/en-us/help/4556400/kb4556400

http://www.nessus.org/u?0a2bc4ce

http://www.nessus.org/u?da286489

http://www.nessus.org/u?e8217353

http://www.nessus.org/u?3a03f407

http://www.nessus.org/u?22034bc1

http://www.nessus.org/u?6206e249

https://support.microsoft.com/en-us/help/4556399/kb4556399

http://www.nessus.org/u?229bf576

http://www.nessus.org/u?52b55515

http://www.nessus.org/u?4aafe901

Plugin Details

Severity: High

ID: 136564

File Name: smb_nt_ms20_may_dotnet.nasl

Version: 1.7

Type: local

Agent: windows

Published: 5/13/2020

Updated: 1/30/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 4

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-1066

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:.net_framework

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/12/2020

Vulnerability Publication Date: 5/12/2020

Exploitable With

Core Impact

Reference Information

CVE: CVE-2020-1066, CVE-2020-1108

IAVA: 2020-A-0207-S

MSFT: MS20-4552926, MS20-4552928, MS20-4552929, MS20-4552931, MS20-4556399, MS20-4556400, MS20-4556401, MS20-4556402, MS20-4556403, MS20-4556404, MS20-4556405, MS20-4556406, MS20-4556441, MS20-4556807, MS20-4556812, MS20-4556813, MS20-4556826

MSKB: 4552926, 4552928, 4552929, 4552931, 4556399, 4556400, 4556401, 4556402, 4556403, 4556404, 4556405, 4556406, 4556441, 4556807, 4556812, 4556813, 4556826