Microsoft
Microsoft .net Framework: vulnerabilidades y CVE
Microsoft .net Framework tiene 202 vulnerabilidades publicadas, 25 de ellas en los últimos 12 meses. 7 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE202
Últimos 12 meses25
Críticas7
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-29059 | Alta (7.5) | 99% | ⚠ Explotación activa | 23 mar 2024 | .NET Framework Information Disclosure Vulnerability |
| CVE-2015-1671 | Alta (7.8) | 49% | ⚠ Explotación activa | 13 may 2015 | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1;… |
| CVE-2020-0646 | Crítica (9.8) | 99% | ⚠ Explotación activa | 14 ene 2020 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. |
| CVE-2020-1147 | Alta (7.8) | 94% | ⚠ Explotación activa | 14 jul 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and… |
| CVE-2017-8759 | Alta (7.8) | 89% | ⚠ Explotación activa | 13 sept 2017 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability." |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-70354 | Alta (7.8) | 0.36% | — | 11 ago 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-65810 | Alta (7.8) | 0.40% | — | 11 ago 2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-62897 | Alta (7) | 0.37% | — | 11 ago 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-62872 | Alta (8.8) | 0.78% | — | 11 ago 2026 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-50659 | Media (6.5) | 0.74% | — | 14 jul 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-50650 | Alta (7.8) | 0.46% | — | 14 jul 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-50649 | Alta (7.8) | 4.0% | — | 14 jul 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50648 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50646 | Alta (7.8) | 4.0% | — | 14 jul 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-50527 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50525 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47304 | Crítica (9.8) | 0.29% | — | 14 jul 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-47302 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50647 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50411 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50368 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50355 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50653 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50652 | Alta (7.5) | 1.7% | — | 14 jul 2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
| CVE-2026-35433 | Alta (7.3) | 0.57% | — | 12 may 2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-32177 | Alta (7.3) | 0.57% | — | 12 may 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-33116 | Alta (7.5) | 2.4% | — | 14 abr 2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. |
| CVE-2026-32226 | Media (5.9) | 0.66% | — | 14 abr 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-23666 | Alta (7.5) | 1.3% | — | 14 abr 2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2025-55248 | Media (5.7) | 0.72% | — | 14 oct 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. |
| CVE-2025-21176 | Alta (8.8) | 2.3% | — | 14 ene 2025 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
| CVE-2024-43484 | Alta (7.5) | 3.0% | — | 8 oct 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43483 | Alta (7.5) | 2.9% | — | 8 oct 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-38081 | Alta (7.3) | 1.3% | — | 9 jul 2024 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability |
| CVE-2024-21409 | Alta (7.3) | 2.5% | — | 9 abr 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.