CVE-2014-0295

Description

VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka VSAVB7RT ASLR Vulnerability.

Risk Information

Base Score
7.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:F/RL:O/RC:C
EPSS Score
Exploitation Probability
19.786

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2901111) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2901111) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2898856) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2898856) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2901110) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2901110) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2898855) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2898855) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack 2 (32-bit) (KB2901115)Windows
Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack 2 (32-bit) (KB2898860)Windows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2901113) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2901113) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2898858) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2898858) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2911502) x86 based systemsWindows
Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2911502) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2901118) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2901118) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898864) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898864) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2901126)Windows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2901126)Windows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898869) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898869) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2901112) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2901112) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2898857) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2898857) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2911501) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2911501) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2901120) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2901120) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2898866) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2898866) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2901119) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2901119) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2898865) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2898865) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2901127) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2901127) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2898870) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2898870) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2901125) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2901125) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2898868) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2898868) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2901128) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2901128) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2898871) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2898871) x64 bases systemsWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-15005Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2901111)
PATCH-15006Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2901111)
PATCH-15007Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2898856)
PATCH-15008Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2003 and Windows XP (KB2898856)
PATCH-15009Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2901110)
PATCH-15010Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2901110)
PATCH-15011Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2898855)
PATCH-15012Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 (KB2898855)
PATCH-15013Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003 Service Pack 2 (32-bit) (KB2901115)
PATCH-15017Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2898858)
PATCH-15018Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2898858)
PATCH-15019Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2911502)
PATCH-15020Security Update for Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB2911502)
PATCH-15021Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2901118)
PATCH-15022Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2901118)
PATCH-15023Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898864)
PATCH-15024Security Update for Microsoft .NET Framework 4.5 on Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898864)
PATCH-15027Security Update for Microsoft .NET Framework 4.5.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898869)
PATCH-15028Security Update for Microsoft .NET Framework 4.5.1 on Windows 7 Service Pack 1, Windows Server 2008 R2 Service Pack 1, Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB2898869)
PATCH-15029Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2901112)
PATCH-15030Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2901112)
PATCH-15031Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2898857)
PATCH-15032Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2898857)
PATCH-15033Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2911501)
PATCH-15034Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB2911501)
PATCH-15035Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2901120)
PATCH-15036Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2901120)
PATCH-15037Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2898866)
PATCH-15038Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB2898866)
PATCH-15039Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2901119)
PATCH-15040Security Update for Microsoft .NET Framework 4.5 on Windows 8, Windows RT and Windows Server 2012 (KB2901119)
PATCH-15043Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2901127)
PATCH-15044Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2901127)
PATCH-15147Security Update for Microsoft .NET Framework 4.5.1 on Windows 8, Windows RT 8, and Windows Server 2012 R2 (KB2898870)
PATCH-15148Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2901125)
PATCH-15149Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2901125)
PATCH-15150Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2898868)
PATCH-15151Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB2898868)
PATCH-15152Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2901128)
PATCH-15153Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2901128)
PATCH-15154Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2898871)
PATCH-15155Security Update for Microsoft .NET Framework 4.5.1 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 (KB2898871)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234