Microsoft .NET Framework CVE-2022-41089 Remote Code Execution Vulnerability

description-logoDescription

Remote Code Execution vulnerability in .NET Framework, .NET, and PowerShell 7.2/7.3 allows a local attacker to execute arbitrary code via crafted input, affecting Windows Server 2022, Windows 10, and .NET Framework 3.5/4.8.1.

affected-products-logoAffected Applications

.NET 7.0
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows RT 8.1
Microsoft .NET Framework 4.8 on Windows RT 8.1
Microsoft Visual Studio 2022 version 17.4
Microsoft Visual Studio 2022 version 17.2
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
Windows Server 2016
Windows Server 2022
Windows Server 2012
Windows 8
Windows 7
Windows 10
Windows Server 2008
Microsoft Visual Studio 2022 version 17.0
.NET 6.0
.NET Core 3.1
Windows 11
Windows Server 2019

Version Updates

Date Version Status Detail
2022-12-14 1.00363
New
.
NET 7.
0,Microsoft .
NET Framework 4.
6.
2/4.
7/4.
7.
1/4.
7.
2 on Windows RT 8.
1,Microsoft .
NET Framework 4.
8 on Windows RT 8.
1,Microsoft Visual Studio 2022 version 17.
4,Microsoft Visual Studio 2022 version 17.
2,Microsoft Visual Studio 2019 version 16.
11 (includes 16.
0 - 16.
10),Windows Server 2016,Windows Server 2022,Windows Server 2012,Windows 8,Windows 7,Windows 10,Windows Server 2008,Microsoft Visual Studio 2022 version 17.
0,.
NET 6.
0,.
NET Core 3.
1,Windows 11,Windows Server 2019