CVE-2014-4072: Medium severity Microsoft .NET Framework vulnerability
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4072?
CVE-2014-4072 has a medium severity rating, primarily due to its potential to cause denial of service.
How do I fix CVE-2014-4072?
Fixing CVE-2014-4072 involves applying the latest security updates provided by Microsoft for the affected .NET Framework versions.
What versions of .NET Framework are affected by CVE-2014-4072?
CVE-2014-4072 affects .NET Framework versions 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.0, 4.5, 4.5.1, and 4.5.2.
What impact does CVE-2014-4072 have on applications?
CVE-2014-4072 can lead to resource consumption and performance degradation in ASP.NET applications.
Who can exploit CVE-2014-4072?
CVE-2014-4072 can be exploited by remote attackers who send crafted requests to the affected .NET applications.