CVE-2024-29059: Microsoft .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
Other sources
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6614Patch KB5034119 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.50727.8976Patch KB5034279 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.50727.8976Patch KB5034278 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5034273 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.30729.8959Patch KB5034269 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.50727.8976Patch KB5034270 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20402Patch KB5034134 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04081.03Fixed in 4.7.04081.02Patch KB5034270 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09214.01Patch KB5033917 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09214.01Patch KB5033920 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09214.01Patch KB5034275 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09214.01Patch KB5034274 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09214.01Patch KB5034272 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.09214.01Patch KB5034276 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04081.03Patch KB5034279 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04081.03Fixed in 4.8.04690.01Patch KB5034269 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04081.03Patch KB5034278 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.04081.03Patch KB5034273 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5034275 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5034274 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5034276 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5034279 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5034278 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Fixed in 4.8.04690.01Patch KB5034269 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.04690.02Patch KB5033910
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-29059?
CVE-2024-29059 is classified as an information disclosure vulnerability in the .NET Framework.
How do I fix CVE-2024-29059?
To remediate CVE-2024-29059, apply the recommended patches provided by Microsoft for affected versions of the .NET Framework.
Which versions of .NET Framework are affected by CVE-2024-29059?
CVE-2024-29059 affects .NET Framework versions 2.0, 3.0, 3.5, 3.5.1, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1.
Are any Windows versions vulnerable to CVE-2024-29059?
Certain Windows versions including Windows Server 2008 and Windows Server 2012 may be indirectly affected through their installed .NET Framework versions.
What type of vulnerability is CVE-2024-29059?
CVE-2024-29059 is designated as an information disclosure vulnerability, which means it could allow unauthorized access to sensitive information.