CVE-2023-36788
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-36788 is a remote code execution vulnerability affecting the Microsoft .NET Framework. Malicious actors can exploit this flaw by sending specially crafted messages to a target system's ASP.NET Web Forms Deserialization feature. Successful exploitation allows the attacker to execute arbitrary code on the affected system, potentially leading to significant security risks. Users are strongly advised to apply the available patches or updates from Microsoft to mitigate this vulnerability. Failure to do so may expose systems to remote code execution attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft .NET Framework
Affected Vendors
- Microsoft