CVE-2014-0257
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers to execute arbitrary code via (1) a crafted web site or (2) a crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 69.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers to execute arbitrary code via (1) a crafted web site or (2) a crafted .NET Framework application that exposes a COM server endpoint, aka "Type Traversal Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 69.69% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- http://packetstormsecurity.com/files/127246/MS14-009-.NET-Deployment-Service-IE-Sandbox-Escape.html
- http://secunia.com/advisories/56793
- http://www.exploit-db.com/exploits/33892
- http://www.osvdb.org/103163
- http://www.securityfocus.com/bid/65417
- http://www.securitytracker.com/id/1029745
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-009
- http://packetstormsecurity.com/files/127246/MS14-009-.NET-Deployment-Service-IE-Sandbox-Escape.html
- http://secunia.com/advisories/56793
- http://www.exploit-db.com/exploits/33892
- http://www.osvdb.org/103163
- http://www.securityfocus.com/bid/65417
- http://www.securitytracker.com/id/1029745
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-009
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.