HIGH
.NET Framework Remote Code Execution Vulnerability
Published Sep 12, 2023
7.8
HIGHCVSS 3.1
EPSS 1.02%
Description
.NET Framework Remote Code Execution Vulnerability
Affected products
-
- Version 2.0.0StatusaffectedConstraints<3.0.30729.8957
- Version
-
- Version 3.0.0StatusaffectedConstraints<3.0.30729.8957
- Version
-
- Version 3.5.0StatusaffectedConstraints<3.0.30729.8957
- Version
-
- Version 3.0.0.0StatusaffectedConstraints<10.0.14393.6252
- Version
-
- Version 4.7.0StatusaffectedConstraints<4.7.04063.05
- Version
-
- Version 4.8.0StatusaffectedConstraints<4.8.04667.03
- Version
-
- Version 4.8.1StatusaffectedConstraints<4.8.09186.01
- Version
-
- Version 4.7.0StatusaffectedConstraints<10.0.10240.20162
- Version
-
- Version 3.5.0StatusaffectedConstraints<3.0.30729.8957
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Microsoft .NET Framework 2.0 Service Pack 2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.0 Service Pack 2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8.1 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 and 4.6.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5.1 | n/a |
|
Configuration 1
AND
- 3.5.1
Running on/with
- r2
Configuration 2
AND
- 3.5
Running on/with
OR
- n/a
- r2
Configuration 3
AND
OR
- 2.0
- 3.0
Running on/with
- n/a
Configuration 4
AND
OR
- 3.5
- 4.8.1
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 5
AND
OR
- 3.5
- 4.8
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 6
AND
OR
- 3.5
- 4.7.2
Running on/with
OR
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 8
dotnet6.0
Not affected
Red Hat Enterprise Linux 8
dotnet7.0
Not affected
Red Hat Enterprise Linux 9
dotnet6.0
Not affected
Red Hat Enterprise Linux 9
dotnet7.0
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | dotnet6.0 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet7.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dotnet6.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dotnet7.0 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This security issue affects Windows systems only.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2023-36788 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2246910 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-40731 Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36788 vendor-advisoryPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-36788
- https://www.cve.org/CVERecord?id=CVE-2023-36788
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-36788 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2246910 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-40731 | Advisory | |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36788 | vendor-advisoryPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-36788 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-36788 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Sep 12, 2023
Updated Oct 30, 2025
Reserved Jun 27, 2023
Link CVE-2023-36788
CISA Vulnrichment
Updated Sep 9, 2024
ENISA EUVD
EUVD-2023-40731 Assigner microsoft
Published Sep 12, 2023
Updated Oct 30, 2025
Exploited since n/a
Link EUVD-2023-40731