MS.NET.Framework.CVE-2024-29059.Information.Disclosure
Description
This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Microsoft .NET Framework.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted request. A remote attacker can exploit this to gain unauthorized access to sensitive information.
Outbreak Alert
Threat Actors are targeting and actively exploiting a Microsoft .NET Framework information disclosure vulnerability (CVE-2024-29059) that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
Affected Products
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 4.6.2
Microsoft .NET Framework 4.7
Microsoft .NET Framework 4.7.1
Microsoft .NET Framework 4.7.2
Microsoft .NET Framework 4.8
Microsoft .NET Framework 4.8.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Impact
Information Disclosure: attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-29059
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |