Microsoft .NET Framework Information Disclosure Vulnerability

CVE-2024-29059
7.5HIGH

Key Information

Vendor
Microsoft
Status
Microsoft .net Framework 4.8
Microsoft .net Framework 3.5 And 4.8
Microsoft .net Framework 3.5 And 4.7.2
Microsoft .net Framework 4.6.2/4.7/4.7.1/4.7.2
Vendor
CVE Published:
23 March 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

A vulnerability in Microsoft .NET Framework, identified as CVE-2024-29059, allows malicious users to obtain sensitive information. This vulnerability affects multiple versions of the .NET Framework, and a high severity rating has been assigned to it. Although there are no known exploits in the wild, affected users are advised to install necessary updates from the KB section listed in Windows Update as a solution to mitigate the risk.

Affected Version(s)

Microsoft .NET Framework 4.8 < 4.8.04690.02

Microsoft .NET Framework 4.8 < 4.8.04690.01

Microsoft .NET Framework 3.5 AND 4.8 < 4.8.04690.02

News Articles

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • First article discovered by Kaspersky Threats

  • Vulnerability published.

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed3 News Article(s)
.