CVE-2014-4072
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 30.94% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- http://blogs.technet.com/b/srd/archive/2014/09/09/assessing-risk-for-the-september-2014-security-updates.aspx
- http://www.securityfocus.com/bid/69603
- http://www.securitytracker.com/id/1030819
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-053
- http://blogs.technet.com/b/srd/archive/2014/09/09/assessing-risk-for-the-september-2014-security-updates.aspx
- http://www.securityfocus.com/bid/69603
- http://www.securitytracker.com/id/1030819
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-053
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.