Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Microsoft · AUTOMATIC DISCOVERY

Microsoft .NET 7

Microsoft .NET is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Microsoft .NET is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductMicrosoft .NET
Release7
End of Support14 May 2024
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2024-29059Added 4 Feb 2025

Microsoft .NET Framework Information Disclosure Vulnerability

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

Microsoft · .NET FrameworkRansomware use: Unknown

CISA entry
CVE-2023-38180Added 9 Aug 2023

Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability

Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).

Microsoft · .NET Core and Visual StudioRansomware use: Unknown

CISA entry
CVE-2020-1147Added 3 Nov 2021

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

Microsoft · .NET Framework, SharePoint, Visual StudioRansomware use: Unknown

CISA entry
CVE-2020-0646Added 3 Nov 2021

Microsoft .NET Framework Remote Code Execution Vulnerability

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

Microsoft · .NET FrameworkRansomware use: Unknown

CISA entry
CVE-2017-8759Added 3 Nov 2021

Microsoft .NET Framework Remote Code Execution Vulnerability

Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.

Microsoft · .NET FrameworkRansomware use: Unknown

CISA entry

Package vulnerability advisories

Checked 9 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2020-1147High severity

.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability

pkg:nuget/Microsoft.NETCore.AppFixed: 2.1.20

OSV record
CVE-2020-1108High severity

.NET Core & .NET Framework Denial of Service Vulnerability

pkg:nuget/Microsoft.NETCore.AppFixed: 2.1.18

OSV record
CVE-2019-0545High severity

Exposure of Sensitive Information in System.Net.Http

pkg:nuget/Microsoft.NETCore.AppFixed: 2.1.7, 2.2.1

OSV record
CVE-2019-0657Medium severity

Improper Input Validation in .Net Framework API's

pkg:nuget/Microsoft.NETCore.AppFixed: 2.2.2, 2.1.8

OSV record

Source evidence

PRIMARYReady

Microsoft .NET official lifecycle source

Version | Original release date | Latest patch version | Patch release date | End of support | .NET 7 | November 8, 2022 | 7.0.20 | May 28, 2024 | May 14, 2024

Official vendor lifecycle or product-change property. Extracted records require human review.

First collected 2 Sep 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source