CVE-2014-4121
Last modified
CVE-2014-4121 is a vulnerability of currently unknown severity. Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability.". EPSS estimates a 19.23% chance of exploitation in the next 30 days.
Description
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | .Net Framework | 2.0 | Sp2 |
| Microsoft | .Net Framework | 3.5 | — |
| Microsoft | .Net Framework | 3.5.1 | — |
| Microsoft | .Net Framework | 4.0 | — |
| Microsoft | .Net Framework | 4.5 | — |
| Microsoft | .Net Framework | 4.5.1 | — |
| Microsoft | .Net Framework | 4.5.2 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4121?
How severe is CVE-2014-4121?
How do I fix CVE-2014-4121?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-4115fastfat.sys (aka the FASTFAT driver) in the kernel-mode driv…
- CVE-2014-4116Cross-site scripting (XSS) vulnerability in Microsoft ShareP…
- CVE-2014-4117Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 an…
- CVE-2014-4118XML Core Services (aka MSXML) 3.0 in Microsoft Windows Serve…
- CVE-2014-4119Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-4120Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-4122Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the A…
- CVE-2014-4123Microsoft Internet Explorer 7 through 11 allows remote attac…8.8
- CVE-2014-4124Microsoft Internet Explorer 7 through 11 allows remote attac…
- CVE-2014-4125Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-4126Microsoft Internet Explorer 10 and 11 allows remote attacker…
- CVE-2014-4127Microsoft Internet Explorer 6 through 10 allows remote attac…
Are you affected by CVE-2014-4121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
