| |
Vulnerability CVE-2014-1806
Published: 2014-05-14
Description: |
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability." |
See advisories in our WLB2 database: | Topic | Author | Date |
High |
| James Forshaw | 17.11.2014 |
Type:
CWE-94 (Improper Control of Generation of Code ('Code Injection'))
CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
10/10 |
10/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Complete |
Complete |
Complete |
References: |
http://www.securityfocus.com/bid/67286
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-026
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|