CVE-2014-0295

EXPLOITED IN THE WILD

Microsoft .NET Framework <3.5.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-0295 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka "VSAVB7RT ASLR Vulnerability."

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029745
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/103164
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65418
Exploit x_refsource_misc
http://www.greyhathacker.net/?p=585
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56793

Scores

EPSS 0.1377
EPSS Percentile 96.1%

Details

VulnCheck KEV 2014-02-12
InTheWild.io 2018-10-12
CWE
CWE-264
Status published
Products (2)
microsoft/.net_framework 2.0 sp2
microsoft/.net_framework 3.5.1
Published Feb 12, 2014
Tracked Since Feb 18, 2026