CVE-2014-4149: Input Validation
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4149?
CVE-2014-4149 has a critical severity rating due to the risk of arbitrary code execution.
How do I fix CVE-2014-4149?
To address CVE-2014-4149, ensure that all affected versions of the Microsoft .NET Framework are updated to the latest security patches provided by Microsoft.
What software is affected by CVE-2014-4149?
CVE-2014-4149 affects Microsoft .NET Framework versions 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2.
Can CVE-2014-4149 be exploited remotely?
Yes, CVE-2014-4149 can be exploited remotely via crafted data sent to a .NET Remoting endpoint.
What type of vulnerability is CVE-2014-4149?
CVE-2014-4149 is classified as a TypeFilterLevel vulnerability, allowing potential elevation of privilege through improper checks.