QID 91939
Date Published: 2022-09-14
QID 91939: Microsoft .NET Framework Remote Code Execution (RCE) Vulnerability for September 2022
A Remote Code Execution (RCE) Vulnerability exist in Microsoft .Net Framework.
Following KBs are covered in this detection:
KB5017498
KB5017501
KB5017315
KB5017367
KB5017365
KB5017370
KB5017377
KB5017361
KB5017373
KB5017497
KB5017500
KB5017499
KB5017358
KB5017371
KB5017305
This security update is rated Important for supported versions of Microsoft .NET Framework.
.NET Framework 2.0, 3.0, 3.5, 3.5.1, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1
QID Detection Logic (Authenticated):
Checks for vulnerable version of ntoskrnl.exe or Mscorlib.dll for the respective .Net Framework KBs
Successful exploitation allows a attacker to cause Remote Code Execution (RCE) Vulnerability.
Solution
Customers are advised to refer to CVE-2022-26929 for more details pertaining to this vulnerability.
Vendor References
- KB5017305 -
support.microsoft.com/help/5017305 - KB5017315 -
support.microsoft.com/help/5017315 - KB5017358 -
support.microsoft.com/help/5017358 - KB5017361 -
support.microsoft.com/help/5017361 - KB5017365 -
support.microsoft.com/help/5017365 - KB5017367 -
support.microsoft.com/help/5017367 - KB5017370 -
support.microsoft.com/help/5017370 - KB5017371 -
support.microsoft.com/help/5017371 - KB5017373 -
support.microsoft.com/help/5017373 - KB5017377 -
support.microsoft.com/help/5017377 - KB5017497 -
support.microsoft.com/help/5017497 - KB5017498 -
support.microsoft.com/help/5017498 - KB5017499 -
support.microsoft.com/help/5017499 - KB5017500 -
support.microsoft.com/help/5017500 - KB5017501 -
support.microsoft.com/help/5017501
CVEs related to QID 91939
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-26929 |
|