Back
CVE-2020-0646
CRITICAL
CISA KEV
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Published: Jan 14, 2020
Modified: Jun 17, 2026
CWE-91
CWE-91
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (28)
| Vendor | Product | Version |
|---|---|---|
| microsoft | .net_framework | 3.0 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.6.2 |
| microsoft | .net_framework | 4.7 |
| microsoft | .net_framework | 4.7.1 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.7.1 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.8 |
| microsoft | .net_framework | 3.5.1 |
| microsoft | .net_framework | 4.5.2 |
| microsoft | .net_framework | 4.6 |
| microsoft | .net_framework | 4.6.2 |
| microsoft | .net_framework | 4.7 |
| microsoft | .net_framework | 4.7.1 |
…and 8 more
GitHub Security Advisory GHSA-4w3v-83v8-mg94
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate...
References (5)
- http://packetstormsecurity.com/files/156930/SharePoint-Workflows-XOML-Injection.html Exploit, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646 Patch, Vendor Advisory
- http://packetstormsecurity.com/files/156930/SharePoint-Workflows-XOML-Injection.html Exploit, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646 Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0646 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
99.22%
Top 0% most likely to be exploited
Threat Score
99 / 100
CISA Known Exploited
Date Added:
2021-11-03
Due Date:
2022-05-03
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS
GitHub