CVE-2024-21409

HIGH

Microsoft .net Framework < 6.0.29 - Use After Free

Title source: rule

Description

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Exploits (1)

nomisec WORKING POC 1 stars
by vkairy · poc
https://github.com/vkairy/cve-2024-21409-repro

Scores

CVSS v3 7.3
EPSS 0.5470
EPSS Percentile 98.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (13)
microsoft/.net 6.0.0 - 6.0.29
microsoft/.net_framework 3.5 (2 CPE variants)
microsoft/.net_framework 4.8.1
microsoft/.net_framework 4.7.2
microsoft/.net_framework 4.8
microsoft/.net_framework 4.6.2
microsoft/.net_framework 4.7
microsoft/.net_framework 4.7.1
microsoft/powershell 7.2 - 7.2.19
microsoft/visual_studio_2022 17.4.0 - 17.4.18
... and 3 more
Published Apr 09, 2024
Tracked Since Feb 18, 2026