Executive brief
A remote code execution vulnerability exists in Microsoft .NET Framework due to improper input validation, specifically involving XOML injection. An attacker can exploit this to execute arbitrary code on a target system without user interaction.
Affected products
- Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8
Timeline
- 2020-02-11: disclosed: Initial release date of the vulnerability advisory by Microsoft.
- 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.