CVE-2024-29059
KEVmass1Information Disclosure in Microsoft .NET Framework
CISA: Microsoft .NET Framework Information Disclosure Vulnerability
CVE-2024-29059 is an information disclosure flaw in Microsoft .NET Framework (CWE-209), in which error handling can generate error messages containing sensitive information. Per the CVSS vector, it is exploitable over the network by an unauthenticated attacker with no user interaction, with high impact to confidentiality only. An attacker who can reach an affected application can trigger the flaw and harvest sensitive details from error output, which can support further attacks against the host or its users. Any organization running affected .NET Framework versions, most commonly on Windows servers hosting ASP.NET/.NET web workloads, is in scope. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-04 with a remediation deadline of 2025-02-25, EPSS puts the 30-day exploitation probability at 98.6%, and no public proof-of-concept is known while ransomware use is unconfirmed.
What to do: Apply Microsoft's current monthly security updates for affected .NET Framework versions as soon as possible, ahead of CISA's February 25, 2025 KEV deadline. Inventory Windows hosts and prioritize internet-facing servers and systems running ASP.NET/.NET Framework applications, confirming installed .NET Framework versions against Microsoft's advisory. If patching must be delayed, follow vendor-recommended mitigations or restrict network access to affected applications until updates are applied.
| Microsoft .NET Framework | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
.NET Framework Information Disclosure Vulnerability
- Affected
- Microsoft .NET Framework
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- .net framework
- Weakness
- CWE-209
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N