CVE-2014-1806 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 39.6% (pctl 99)
Patch early
A public exploit exists.
Description
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 39.59% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-05-14 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | .net framework |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | .NET Remoting Services - Remote Command Execution | 2014-11-17 |
References
→ the Explorer · watch your stack · NVD