CVE-2014-0295: Medium severity Microsoft .NET Framework vulnerability
Published Feb 12, 2014
·Updated
VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka "VSAVB7RT ASLR Vulnerability."
Affected Software
2 affected components
Microsoft .NET Framework=2.0-sp2
Microsoft .NET Framework=3.5.1
Event History
Feb 12, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:50 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0295?
CVE-2014-0295 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2014-0295?
To fix CVE-2014-0295, update to a version of the Microsoft .NET Framework that includes the ASLR protection mechanism.
3
Who is affected by CVE-2014-0295?
CVE-2014-0295 affects users of Microsoft .NET Framework 2.0 SP2 and 3.5.1.
4
What types of attacks exploit CVE-2014-0295?
CVE-2014-0295 can be exploited through crafted websites to execute arbitrary code on affected systems.
5
When was CVE-2014-0295 first exploited in the wild?
CVE-2014-0295 was first exploited in the wild in February 2014.