KLA11772
Multiple vulnerabilities in Microsoft Developer Tools
Обновлено: 18/06/2020
Дата обнаружения
12/05/2020
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to gain privileges, cause denial of service, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in .NET Framework can be exploited remotely to gain privileges.
  2. A denial of service vulnerability in .NET Core & .NET Framework can be exploited remotely via specially crafted requests to cause denial of service.
  3. A denial of service vulnerability in ASP.NET Core can be exploited remotely via specially crafted requests to cause denial of service.
  4. A remote code execution vulnerability in Visual Studio Code Python Extension can be exploited remotely to execute arbitrary code.
  5. A remote code execution vulnerability in Visual Studio Code Python Extension can be exploited remotely via specially crafted file to execute arbitrary code.
Эксплуатация

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Пораженные продукты

Microsoft .NET Framework 3.5
Microsoft .NET Framework 4.5.2
ASP.NET Core 3.1
Microsoft .NET Framework 4.6
Microsoft Visual Studio 2019 version 16.5
Microsoft Visual Studio 2017 version 15.9 (includes 15.1 - 15.8)
Microsoft .NET Framework 3.5 AND 4.6/4.6.1/4.6.2
Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 4.8
.NET Core 3.1
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 3.5 AND 4.7.2
.NET Core 5.0
.NET Core 2.1
Visual Studio Code
Microsoft .NET Framework 3.5 AND 4.8
Microsoft Visual Studio 2019 version 16.0
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-1066
CVE-2020-1108
CVE-2020-1161
CVE-2020-1171
CVE-2020-1192
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

PE 
[?]
Связанные продукты
Microsoft .NET Framework
Microsoft Visual Studio
CVE-IDS
CVE-2020-10660.0Unknown
CVE-2020-11080.0Unknown
CVE-2020-11610.0Unknown
CVE-2020-11710.0Unknown
CVE-2020-11920.0Unknown
KB list

4556826
4556813
4556812
4556807
4556406
4556405
4556404
4556403
4556402
4556401
4556400
4556441
4552929
4552926
4552931
4556399
4552928

Microsoft official advisories
Microsoft Security Update Guide