← All CVEs

CVE-2014-4073

high · 10

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."

10
CVSS
23.4%
EPSS (exploit prob.)
98th
EPSS percentile
2014-10-15
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoft.net_framework2.0
microsoft.net_framework3.5
microsoft.net_framework3.5.1
microsoft.net_framework4.0
microsoft.net_framework4.5
microsoft.net_framework4.5.1
microsoft.net_framework4.5.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-4073