Executive brief
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input via malicious documents or applications. An attacker who successfully exploits this vulnerability could take complete control of an affected system.
Affected products
- Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7
Timeline
- 2017-09-12: advisory: MSRC advisory published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed: NVD publication date