CVE-2020-0646: Microsoft .NET Framework Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 99.2% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Affected products
- Microsoft .NET Framework: version 3.0 only; version 3.5 only; version 4.6.2 only; version 4.7 only; version 4.7.1 only; version 4.7.2 only; …
Published 2020-01-14. Last modified 2026-06-17.