Check Point Reference: | CPAI-2014-1887 |
Date Published: | 14 Oct 2014 |
Severity: | Critical |
Last Updated: | Tuesday 14 October, 2014 |
Source: | Microsoft Security Bulletin MS14-057 |
Industry Reference: | CVE-2014-4121 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4 Microsoft .NET Framework 4.5/4.5.1/4.5.2 |
Vulnerability Description | A remote code execution vulnerability has been reported in the Microsoft .NET Framework. The vulnerability is due to the way .NET framework parses internationalized resource identifiers. A remote attacker could exploit this vulnerability by sending specially crafted data to the target server that uses .NET framework. |
Update/Patch Avaliable | Apply patches from: MS14-057 |
SmartView Tracker will log the following entries:
Attack Name: Content Protection Violation.
Attack Information: Microsoft .NET Framework Remote Code Execution (MS14-057: CVE-2014-4121)