- Notifications
You must be signed in to change notification settings - Fork1.2k
Security: dotnet/wpf
Security
SECURITY.md
The .NET Core and ASP.NET Core support policy, including supported versions can be found at the.NET Core Support Policy Page.
Security issues and bugs should be reported privately, via email, to the Microsoft Security Response Center (MSRC) thoughhttps://msrc.microsoft.com or by emailingsecure@microsoft.com.You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received youroriginal message. Further information, including the MSRC PGP key, can be found in theMSRC Report an Issue FAQ.
Reports via MSRC may qualify for the .NET Core Bug Bounty. Details of the .NET Core Bug Bounty including terms and conditions are athttps://aka.ms/corebounty.
Please do not open issues for anything you think might have a security implication.
- Microsoft Security Advisory CVE-2024-21409 | .NET Elevation of Privilege VulnerabilityGHSA-6qmx-42h2-j8h6 published
Apr 9, 2024 byrbhandaCritical - Microsoft Security Advisory CVE-2023-24895: .NET Remote Code Execution VulnerabilityGHSA-jh2h-qcrw-ghg7 published
Jun 13, 2023 byrbhandaCritical - .NET Remote Code Execution VulnerabilityGHSA-2c7v-qcjp-4mg2 published
Dec 14, 2022 byrbhandaCritical