MS.NET.Framework.CVE-2024-29059.Information.Disclosure

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Microsoft .NET Framework.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted request. A remote attacker can exploit this to gain unauthorized access to sensitive information.

description-logoOutbreak Alert

Threat Actors are targeting and actively exploiting a Microsoft .NET Framework information disclosure vulnerability (CVE-2024-29059) that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

View the full Outbreak Alert Report

affected-products-logoAffected Products

Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 4.7
Microsoft .NET Framework 4.7.1
Microsoft .NET Framework 4.7.2
Microsoft .NET Framework 4.8
Microsoft .NET Framework 4.8.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2

Impact logoImpact

Information Disclosure: attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-29059

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-08-04 33.057
Modified
Sig Added
2025-02-19 30.957
Modified
Default_action:pass:drop
2025-02-12 30.953
New