CVE-2022-26929

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 13, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-26929 is a remote code execution vulnerability affecting the .NET Framework. Maliciously crafted aspx or axd files can exploit this issue, leading to arbitrary code execution when a user visits a specially crafted website. Attackers can leverage this flaw to install malware, steal sensitive data, or take control of affected systems. Microsoft released a security patch to address this vulnerability, and it's recommended to apply the update as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft .NET Framework

Affected Vendors

  • Microsoft