QID 91868

Date Published: 2022-03-09

QID 91868: Microsoft .NET Security Update for March 2022

Microsoft has released a security Update for .NET which resolves Denial of Service and Remote Code Execution Vulnerabilities.
This security update is rated Important for supported versions of .NET

Affected versions:
.NET 5.0 before version 5.0.15
.NET 6.0 before version 6.0.3
and .NET Core 3.1 before version 3.1.23

QID Detection Logic: Authenticated

This QID detects vulnerable versions of Microsoft .NET Core by checking the file version on windows.

Successful exploitation of this vulnerability could lead to Denial of Service and Remote Code Execution Vulnerabilities.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to CVE-2022-24512, CVE-2022-24464, and CVE-2020-8927 for more information pertaining to these vulnerabilities.

    CVEs related to QID 91868

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-8927 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2020-8927
    CVE-2022-24464 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24464
    CVE-2022-24512 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24512