CVE-2014-0257: Input Validation
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers to execute arbitrary code via (1) a crafted web site or (2) a crafted .NET Framework application that exposes a COM server endpoint, aka "Type Traversal Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0257?
CVE-2014-0257 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2014-0257?
To fix CVE-2014-0257, apply the latest security updates from Microsoft for the affected .NET Framework versions.
Which versions of .NET Framework are affected by CVE-2014-0257?
CVE-2014-0257 affects Microsoft .NET Framework versions 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4.0, 4.5, and 4.5.1.
Can CVE-2014-0257 be exploited through a web application?
Yes, CVE-2014-0257 can be exploited via a crafted website that takes advantage of the vulnerability.
What types of attacks are possible with CVE-2014-0257?
CVE-2014-0257 allows remote attackers to execute arbitrary code, potentially compromising the host system.