CVE-2014-1806

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.5.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/67286 - VDB Entry () http://www.securityfocus.com/bid/67286 - VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-026 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-026 -

Information

Published : 2014-05-14 11:13

Updated : 2024-11-21 02:05


NVD link : CVE-2014-1806

Mitre link : CVE-2014-1806

CVE.ORG link : CVE-2014-1806


JSON object : View

Products Affected

microsoft

  • .net_framework
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')