CVE-2014-4121
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, y 4.5.2 no analiza debidamente los identificadores de los recursos internacionalizados, lo que permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de una solicitud manipulada en una aplicación de web .NET web, también conocido como 'vulnerabilidad de la ejecución de código remoto en .NET Framework.'
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-06-12 CVE Reserved
- 2014-10-15 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/60969 | Third Party Advisory | |
http://www.securityfocus.com/bid/70351 | Vdb Entry | |
http://www.securitytracker.com/id/1031021 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-057 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 2.0 Search vendor "Microsoft" for product ".net Framework" and version "2.0" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 3.5 Search vendor "Microsoft" for product ".net Framework" and version "3.5" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 3.5.1 Search vendor "Microsoft" for product ".net Framework" and version "3.5.1" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 4.0 Search vendor "Microsoft" for product ".net Framework" and version "4.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 4.5 Search vendor "Microsoft" for product ".net Framework" and version "4.5" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 4.5.1 Search vendor "Microsoft" for product ".net Framework" and version "4.5.1" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | .net Framework Search vendor "Microsoft" for product ".net Framework" | 4.5.2 Search vendor "Microsoft" for product ".net Framework" and version "4.5.2" | - |
Affected
|