.Net Framework

by Microsoft

Take action — actively targeted

.Net Framework is actively targeted by attackers. A significant proportion of its known vulnerabilities are being exploited.

What to do
  1. Apply all available updates immediately
  2. Review your exposure — is this internet-facing?
  3. Monitor vendor advisories for this product

What Attackers Target

Vulnerabilities with high exploit probability 44.7%
Confirmed actively exploited (CISA) 5.9%
Public exploit code available 5.9%
Based on 85 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.

Most Dangerous Vulnerabilities

CVE CVSS Exploit Probability Confirmed
CVE-2017-8759 7.8 94.0% Yes
CVE-2020-0646 9.8 93.9% Yes
CVE-2024-29059 7.5 93.8% Yes
CVE-2020-1147 7.8 93.4% Yes
CVE-2015-1671 7.8 85.9% Yes
CVE-2016-0145 8.8 74.8%
CVE-2023-36899 8.8 70.0%
CVE-2018-8421 9.8 55.0%
CVE-2024-21409 7.3 54.7%
CVE-2012-0014 7.8 52.3%
CVE-2013-3129 7.8 51.7%
CVE-2009-2502 8.1 47.5%
CVE-2016-7270 7.5 37.0%
CVE-2018-0764 7.5 34.7%
CVE-2020-0605 8.8 34.1%
CVE-2019-1113 8.8 33.7%
CVE-2018-8260 8.8 33.2%
CVE-2016-0132 9.8 32.6%
CVE-2020-0606 8.8 32.3%
CVE-2018-8284 8.1 30.2%
58
/ 100
high-risk
Active Threat 50/50 · Critical
Exploit Availability 8/50 · Minimal

Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.