High severity7.8NVD Advisory· Published May 21, 2020· Updated Aug 19, 2026
CVE-2020-1066
CVE-2020-1066
Description
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects.
Affected products
6cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
- (no CPE)range: Windows 7 for 32-bit Systems Service Pack 1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.