Lucene search

K
cve[email protected]CVE-2014-0295
HistoryFeb 12, 2014 - 4:50 a.m.

CVE-2014-0295

2014-02-1204:50:41
CWE-264
web.nvd.nist.gov
34
cve-2014-0295
microsoft .net framework
aslr
vsavb7rt
vulnerability
nvd
remote code execution

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

Low

0.034 Low

EPSS

Percentile

91.5%

VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka “VSAVB7RT ASLR Vulnerability.”

Affected configurations

NVD
Node
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

Low

0.034 Low

EPSS

Percentile

91.5%