Description
.NET Framework Information Disclosure Vulnerability
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
E
Unchanged
RL
O
RC
Changed
Affected products
- Microsoft / Microsoft .NET Framework 2.0 Service Pack 22.0.0 – 3.0.50727.8976
- Microsoft / Microsoft .NET Framework 3.0 Service Pack 23.0.0 – 3.0.50727.8976
- Microsoft / Microsoft .NET Framework 3.53.5.0 – 3.0.50727.8976
- Microsoft / Microsoft .NET Framework 3.5.13.5.0 – 3.0.30729.8959
- Microsoft / Microsoft .NET Framework 3.5 AND 4.6/4.6.210.0.0 – 10.0.10240.20402
- Microsoft / Microsoft .NET Framework 3.5 AND 4.7.24.7.0 – 4.7.04081.03
- Microsoft / Microsoft .NET Framework 3.5 AND 4.84.8.0 – 4.8.04690.02
- Microsoft / Microsoft .NET Framework 3.5 AND 4.8.14.8.1 – 4.8.09214.01
- Microsoft / Microsoft .NET Framework 4.6.24.7.0 – 4.7.04081.03
- Microsoft / Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.24.7.0 – 4.7.04081.03
- Microsoft / Microsoft .NET Framework 4.84.8.0 – 4.8.04690.02
Exploits & proofs of concept
- nuclei.NET Framework - Leaking ObjRefs via HTTP .NET Remotingby iamnoooob,rootxharsh,DhiyaneshDk,pdresearch