CVE-2014-4149
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@microsoft.com — http://blogs.technet.com/b/srd/archive/2014/11/11/ms14-072-net-remoting-elevation-of-privilege-vulnerability.aspx
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | .net_framework | 1.1 | |
| microsoft | .net_framework | 2.0 | |
| microsoft | .net_framework | 3.5 | |
| microsoft | .net_framework | 3.5.1 | |
| microsoft | .net_framework | 4.0 | |
| microsoft | .net_framework | 4.5 | |
| microsoft | .net_framework | 4.5.1 | |
| microsoft | .net_framework | 4.5.2 | |
References
- http://blogs.technet.com/b/srd/archive/2014/11/11/ms14-072-net-remoting-elevation-of-privilege-vulnerability.aspx
- http://www.securitytracker.com/id/1031188
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-072
- http://blogs.technet.com/b/srd/archive/2014/11/11/ms14-072-net-remoting-elevation-of-privilege-vulnerability.aspx
- http://www.securitytracker.com/id/1031188
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-072
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.