CVE-2014-4073: Critical severity Microsoft .NET Framework vulnerability
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4073?
CVE-2014-4073 has a severity rating categorized as 'important' due to the potential for privilege escalation.
How do I fix CVE-2014-4073?
To fix CVE-2014-4073, Microsoft recommends applying the latest security updates for the .NET Framework.
What versions of Microsoft .NET Framework are affected by CVE-2014-4073?
CVE-2014-4073 affects Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2.
What type of vulnerability is CVE-2014-4073?
CVE-2014-4073 is classified as an Elevation of Privilege vulnerability which allows remote attackers to gain higher access rights.
Can CVE-2014-4073 be exploited remotely?
Yes, CVE-2014-4073 can be exploited remotely through unverified data interaction with the ClickOnce installer.