CVE-2020-0646
Microsoft .NET Framework Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 99.2% 백분위 99.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.05.03
- 공개일
- 2020.01.15
CISA KEV에 등록된 실제 악용 확인 취약점
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
공급사 Microsoft
제품 .NET Framework
영향 버전 Windows 7 for 32-bit Systems Service Pack 1, Windows 7 for x64-based Systems Service Pack 1, Windows 8.1 for 32-bit systems, Windows 8.1 for x64-based systems, Windows RT 8.1, Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607 for 32-bit Systems, unspecified, 1903, Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2, Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2, Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2, Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
수정 버전 공식 출처에서 확인 필요
Apply updates per vendor instructions.
조치 기한: 2022.05.03CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-91
KEV 등록일 2021.11.03
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2020-0646
EPSS 데이터 기준일 2026.06.27