CVE-2014-4121: Critical severity Microsoft .NET Framework vulnerability
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4121?
CVE-2014-4121 is rated as critical due to its potential for remote code execution and denial of service.
How do I fix CVE-2014-4121?
To fix CVE-2014-4121, apply the latest security updates provided by Microsoft for the affected .NET Framework versions.
What is the impact of CVE-2014-4121?
CVE-2014-4121 can allow attackers to execute arbitrary code or cause memory corruption in .NET web applications.
Which versions of the .NET Framework are affected by CVE-2014-4121?
CVE-2014-4121 affects Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2.
How can an attacker exploit CVE-2014-4121?
An attacker can exploit CVE-2014-4121 by sending a specially crafted request to a vulnerable .NET web application.