CVE-2020-16937: Microsoft .NET Framework
Medium severity, CVSS 4.7. EPSS: 3.3% chance of exploitation in the next 30 days.
<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p> <p>To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.</p> <p>The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.</p>
Affected products
- Microsoft .NET Framework: version 2.0 only; version 3.5 only; version 4.6.2 only; version 4.7 only; version 4.7.1 only; version 4.7.2 only; …
Published 2020-10-16. Last modified 2026-06-17.