.NET Framework Remote Code Execution Vulnerability
Published Jun 14, 2023
7.8
HIGHCVSS 3.1
EPSS 0.90%
Description
.NET Framework Remote Code Execution Vulnerability
Affected products
-
- Version 2.0.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 3.0.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 3.5.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 3.0.0.0StatusaffectedConstraints<10.0.14393.5989
- Version
-
- Version 4.7.0StatusaffectedConstraints<4.7.4050.0
- Version
-
- Version 4.8.0StatusaffectedConstraints<4.8.4644.0
- Version
-
- Version 4.8.1StatusaffectedConstraints<4.8.9166.0
- Version
-
- Version 4.7.0StatusaffectedConstraints<10.0.10240.19983
- Version
-
- Version 3.5.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Microsoft .NET Framework 2.0 Service Pack 2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.0 Service Pack 2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8.1 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 and 4.6.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5.1 | n/a |
|
Configuration 1
- 3.5.1
Running on/with
- r2
Configuration 2
- 3.5
- 4.6.2
Running on/with
- n/a
- n/a
Configuration 3
- 3.5
- 4.8.1
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 4
- 3.5
- 4.8
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 5
- 3.5
- 4.7.2
Running on/with
- n/a
- n/a
- n/a
Configuration 6
- 3.5
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
Running on/with
- n/a
- n/a
- n/a
Configuration 7
- 3.5
Running on/with
- n/a
- r2
Configuration 8
- 3.0
Running on/with
- n/a
- n/a
Configuration 9
- 2.0
Running on/with
- n/a
- n/a
No data.
.NET 6.0 on Red Hat Enterprise Linux
rh-dotnet60-dotnet
Not affected
Red Hat Enterprise Linux 8
dotnet6.0
Not affected
Red Hat Enterprise Linux 8
dotnet7.0
Not affected
Red Hat Enterprise Linux 9
dotnet6.0
Not affected
Red Hat Enterprise Linux 9
dotnet7.0
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET 6.0 on Red Hat Enterprise Linux | rh-dotnet60-dotnet | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet6.0 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet7.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dotnet6.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dotnet7.0 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (6)
- https://access.redhat.com/security/cve/CVE-2023-29326 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2215133 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32901 Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29326 vendor-advisoryPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-29326
- https://www.cve.org/CVERecord?id=CVE-2023-29326
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-29326 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2215133 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32901 | Advisory | |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29326 | vendor-advisoryPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-29326 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-29326 |
Change history (0)
No recorded changes yet.