CVE-2019-1113: Microsoft .NET Framework

High severity, CVSS 8.8. EPSS: 10% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.

Affected products

  • Microsoft .NET Framework: version 2.0 only; version 3.0 only; version 3.5 only; version 4.7.2 only; version 4.8 only; version 3.5.1 only; …
  • Microsoft Visual Studio 2017: affected versions not specified; version 15.9 only; version 16.0 only; version 16.1 only

Published 2019-07-15. Last modified 2026-06-17.