HIGH8.8
GHSA-r4mw-gxf7-vxr9
Remote code execution in Microsoft.WindowsDesktop.App.Ref
Quick fix
GHSA-r4mw-gxf7-vxr9 — Microsoft.WindowsDesktop.App.Ref: upgrade to the fixed version with the command below.
dotnet add package Microsoft.WindowsDesktop.App.Ref --version 3.0.2Details
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Microsoft.WindowsDesktop.App.Ref
Introduced in:
3.0.1Fixed in: 3.0.2Fix
dotnet add package Microsoft.WindowsDesktop.App.Ref --version 3.0.2NuGet/Microsoft.WindowsDesktop.App.Ref
Introduced in:
3.1.0Fixed in: 3.1.1Fix
dotnet add package Microsoft.WindowsDesktop.App.Ref --version 3.1.1NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x86
Introduced in:
3.0.0Fixed in: 3.0.2Fix
dotnet add package Microsoft.WindowsDesktop.App.Runtime.win-x86 --version 3.0.2NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x86
Introduced in:
3.1.0Fixed in: 3.1.11Fix
dotnet add package Microsoft.WindowsDesktop.App.Runtime.win-x86 --version 3.1.11NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x64
Introduced in:
3.0.0Fixed in: 3.0.2Fix
dotnet add package Microsoft.WindowsDesktop.App.Runtime.win-x64 --version 3.0.2NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x64
Introduced in:
3.1.0Fixed in: 3.1.11Fix
dotnet add package Microsoft.WindowsDesktop.App.Runtime.win-x64 --version 3.1.11