peter bassill · operator
$ cve CVE-2014-1806 JSON

CVE-2014-1806 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 39.6% (pctl 99)

Patch early

A public exploit exists.

Description

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS39.59% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2014-05-14
Last modified2026-06-17

Affected (1)

VendorProduct
microsoft.net framework

Public exploits

SourceTitleDate
exploit-db.NET Remoting Services - Remote Command Execution2014-11-17

References

→ the Explorer  ·  watch your stack  ·  NVD