CVE Vulnerabilities

CVE-2014-4073

Published: Oct 15, 2014 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka .NET ClickOnce Elevation of Privilege Vulnerability.

Affected Software

Name Vendor Start Version End Version
.net_framework Microsoft 2.0-sp2 (including) 2.0-sp2 (including)
.net_framework Microsoft 3.5 (including) 3.5 (including)
.net_framework Microsoft 3.5.1 (including) 3.5.1 (including)
.net_framework Microsoft 4.0 (including) 4.0 (including)
.net_framework Microsoft 4.5 (including) 4.5 (including)
.net_framework Microsoft 4.5.1 (including) 4.5.1 (including)
.net_framework Microsoft 4.5.2 (including) 4.5.2 (including)

References