Microsoft .NET Framework Information Disclosure Vulnerability
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
CISA entryMicrosoft · AUTOMATIC DISCOVERY
Microsoft .NET is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
Microsoft .NET is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used by software teams to build, run or maintain applications.
Included in source projects, application dependencies, build systems or managed runtimes.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Microsoft .NET |
|---|---|
| Release | 3.1 |
| End of Support | 13 December 2022 |
| Date precision | Day |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
CISA entryMicrosoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).
CISA entryMicrosoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
CISA entryMicrosoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.
CISA entryMicrosoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.
CISA entryOSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
Version | Original release date | Latest patch version | Patch release date | End of support | .NET Core 3.1 | December 3, 2019 | 3.1.32 | December 13, 2022 | December 13, 2022
Official vendor lifecycle or product-change property. Extracted records require human review.
Open official vendor source