CVE-2021-26701 is a critical Remote Code Execution vulnerability affecting various Microsoft .NET, .NET Core, PowerShell Core, and Visual Studio 2019 products, as well as Fedora Project derivatives. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community discussion and media coverage, including warnings from Microsoft. Despite its high risk score and media attention, it is not listed on CISA's Known Exploited Vulnerabilities catalog and is currently inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.0.4CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 2.1, < 2.1.28CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:* | ||
>= 3.1, < 3.1.15CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell_core:7.0:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell_core:7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS
May 24, 2023.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS
May 24, 2023.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS
May 24, 2023.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS
May 24, 2023.NET Core Remote Code Execution Vulnerability
Apr 21, 2021dotnet: System.Text.Encodings.Web Remote Code Execution
Feb 25, 2021.NET Core Remote Code Execution Vulnerability
Feb 9, 2021