Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2020-1066
Microsoft Microsoft .NET Framework 3.0 Service Pack 2 — .NET Framework Elevation of Privilege Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0250 84.2 —
AFFECTED
Product Versions Fixed
Microsoft .NET Framework 3.0 Service Pack 2 3.0.0 – —
Microsoft .NET Framework 3.5.1 3.5.0 – —
TIMELINE
Nov 4 Reserved by microsoft
May 21 Published (CNA: microsoft)
Aug 19 ENRICHED — CVE-2020-1066 (Microsoft .NET Framework 3.0 Service Pack 2). Received CVSS 7.8 and CPE data from NVD.
Description
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.
To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.
The update addresses the vulnerability by correcting how .NET Framework activates COM objects.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| November 4, 2019 | Reserved | Reserved by microsoft |
| May 21, 2020 | Published | Published (CNA: microsoft) |
| August 19, 2026 | ENRICHED | ENRICHED — CVE-2020-1066 (Microsoft .NET Framework 3.0 Service Pack 2). Received CVSS 7.8 and CPE data from NVD. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Microsoft | Microsoft .NET Framework 3.0 Service Pack 2 | — | 3.0.0 | — |
| Microsoft | Microsoft .NET Framework 3.5.1 | — | 3.5.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2020-1066 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.