High severity8.8NVD Advisory· Published Jan 14, 2020· Updated Jun 17, 2026
CVE-2020-0603
CVE-2020-0603
Description
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.AllNuGet | >= 2.1.0, < 2.1.15 | 2.1.15 |
Microsoft.AspNetCore.AppNuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.AppNuGet | >= 3.0.0, < 3.0.1 | 3.0.1 |
Microsoft.AspNetCore.AppNuGet | >= 2.1.0, < 2.1.15 | 2.1.15 |
Microsoft.AspNetCore.Http.ConnectionsNuGet | >= 1.0.0, < 1.0.15 | 1.0.15 |
Microsoft.AspNetCore.App.Runtime.linux-armNuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.win-armNuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 3.1.0, < 3.1.1 | 3.1.1 |
Affected products
19cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:3.1:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
- osv-coords13 versionspkg:bitnami/aspnet-corepkg:nuget/microsoft.aspnetcore.allpkg:nuget/microsoft.aspnetcore.apppkg:nuget/microsoft.aspnetcore.app.runtime.linux-armpkg:nuget/microsoft.aspnetcore.app.runtime.linux-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-x64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-x64pkg:nuget/microsoft.aspnetcore.app.runtime.osx-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-armpkg:nuget/microsoft.aspnetcore.app.runtime.win-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-x86pkg:nuget/microsoft.aspnetcore.http.connections
>= 2.1.0, < 2.1.1+ 12 more
- (no CPE)range: >= 2.1.0, < 2.1.1
- (no CPE)range: >= 2.1.0, < 2.1.15
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 3.1.0, < 3.1.1
- (no CPE)range: >= 1.0.0, < 1.0.15
Patches
Vulnerability mechanics
References
7- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603nvdPatchVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0130nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0134nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-655q-9gvg-q4cmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-0603ghsaADVISORY
- github.com/aspnet/Announcements/issues/403ghsaWEB
- github.com/github/advisory-database/issues/302ghsaWEB
News mentions
0No linked articles in our index yet.