Microsoft .NET Framework Information Disclosure

Released: Mar 17, 2025



Exposure of Sensitive Information

Threat Actors are targeting and actively exploiting a Microsoft .NET Framework information disclosure vulnerability (CVE-2024-29059) that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. Learn More »

Common Vulnerabilities and Exposures


Background

The security vulnerability tracked as CVE-2024-29059, has also been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on February 4, 2025.

The vulnerability can be exploited remotely over the network, with low complexity and without any user interaction, making it relatively easy to exploit once the target is identified.

FortiGuard Sensors continuously detect a steady stream of attack attempts and have blocked attack attempts across up to 1,200 devices.

Latest Development

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.


FortiGuard recommends users to apply the latest security updates provided by Micosoft and follow instructions as mentioned on the vendor’s advisory. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29059

FortiGuard Cybersecurity Framework

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.


PROTECT
  • Lure

  • Decoy VM

  • Vulnerability

  • IPS

DETECT
  • IOC

  • Outbreak Detection

  • Threat Hunting

  • Content Update

RESPOND
  • Automated Response

  • Assisted Response Services

RECOVER
  • NOC/SOC Training

  • End-User Training

IDENTIFY
  • Vulnerability Management

  • Attack Surface Monitoring (Inside & Outside)

  • Attack Surface Hardening

Threat Intelligence

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.