Microsoft .NET Framework是美国微软(Microsoft)公司的一种全面且一致的编程模型,也是一个用于构建Windows、Windows Store、Windows Phone、Windows Server和Microsoft Azure的应用程序的开发平台。该平台包括C#和Visual Basic编程语言、公共语言运行库和广泛的类库。 Microsoft .NET Framework存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft .NET Framework 4.8 | 4.8.0 ~ 4.8.04690.02 | - |
|
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | 4.8.0 ~ 4.8.04690.02 | - |
|
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | 4.7.0 ~ 4.7.04081.03 | - |
|
| Microsoft | Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 | 4.7.0 ~ 4.7.04081.03 | - |
|
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8.1 | 4.8.1 ~ 4.8.09214.01 | - |
|
| Microsoft | Microsoft .NET Framework 4.6.2 | 4.7.0 ~ 4.7.04081.03 | - |
|
| Microsoft | Microsoft .NET Framework 3.5 AND 4.6/4.6.2 | 10.0.0 ~ 10.0.10240.20402 | - |
|
| Microsoft | Microsoft .NET Framework 2.0 Service Pack 2 | 2.0.0 ~ 3.0.50727.8976 | - |
|
| Microsoft | Microsoft .NET Framework 3.0 Service Pack 2 | 3.0.0 ~ 3.0.50727.8976 | - |
|
| Microsoft | Microsoft .NET Framework 3.5 | 3.5.0 ~ 3.0.50727.8976 | - |
|
| Microsoft | Microsoft .NET Framework 3.5.1 | 3.5.0 ~ 3.0.30729.8959 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059) | https://github.com/codewhitesec/HttpRemotingObjRefLeak | POC Details |
| 2 | .NET Framework Information Disclosure Vulnerability | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29059.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-26247 | 4.7 MEDIUM | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2024-29057 | 4.3 MEDIUM | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
No comments yet