CVE-2014-0295
EXPLOITED IN THE WILDMicrosoft .NET Framework <3.5.1 - RCE
Title source: llmExploitation Summary
CVE-2014-0295 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
Description
VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka "VSAVB7RT ASLR Vulnerability."
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1029745
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/103164
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65418
Exploit x_refsource_misc
http://www.greyhathacker.net/?p=585
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56793
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-009
Scores
EPSS
0.1377
EPSS Percentile
96.1%
Details
VulnCheck KEV
2014-02-12
InTheWild.io
2018-10-12
CWE
CWE-264
Status
published
Products (2)
microsoft/.net_framework
2.0 sp2
microsoft/.net_framework
3.5.1
Published
Feb 12, 2014
Tracked Since
Feb 18, 2026