logo

CVE-2023-36049: Microsoft .NET CRLF Injection Arbitrary File Write/Deletion Vulnerability

ID: c507f966-ee10-56a4-9e92-869c246008ca

STIX ID: report--c507f966-ee10-56a4-9e92-869c246008ca

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
50/100

Date Published: 2024-03-06

Date Updated: 2026-05-01

Author: Trend Micro Research Team

...
...

This report analyzes CVE-2023-36049, an FTP-URI handling vulnerability affecting PowerShell (including versions 7.2–7.4) for which Microsoft released patches in November. It gives detection guidance—monitor FTP traffic on TCP/21 and flag packets containing multiple FTP commands (multiple CRLFs)—and recommends applying the vendor patch or refusing/filtering FTP URIs from untrusted peers as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.