ZeroHour

CVE-2024-29059

KEVmass1

Information Disclosure in Microsoft .NET Framework

CISA: Microsoft .NET Framework Information Disclosure Vulnerability

CVSS 3.1
7.5 high
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2024-29059 is an information disclosure flaw in Microsoft .NET Framework (CWE-209), in which error handling can generate error messages containing sensitive information. Per the CVSS vector, it is exploitable over the network by an unauthenticated attacker with no user interaction, with high impact to confidentiality only. An attacker who can reach an affected application can trigger the flaw and harvest sensitive details from error output, which can support further attacks against the host or its users. Any organization running affected .NET Framework versions, most commonly on Windows servers hosting ASP.NET/.NET web workloads, is in scope. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-04 with a remediation deadline of 2025-02-25, EPSS puts the 30-day exploitation probability at 98.6%, and no public proof-of-concept is known while ransomware use is unconfirmed.

What to do: Apply Microsoft's current monthly security updates for affected .NET Framework versions as soon as possible, ahead of CISA's February 25, 2025 KEV deadline. Inventory Windows hosts and prioritize internet-facing servers and systems running ASP.NET/.NET Framework applications, confirming installed .NET Framework versions against Microsoft's advisory. If patching must be delayed, follow vendor-recommended mitigations or restrict network access to affected applications until updates are applied.

Affected
Microsoft .NET Framework
Estimated exposure
massmillions of Windows systems (component ships with Windows and underpins a large share of enterprise web workloads) — .NET Framework is bundled with modern Windows client and server releases and is widely used for enterprise ASP.NET applications, so exposure scales with the very large Windows/IIS installed base rather than a discrete product install count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

.NET Framework Information Disclosure Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft .NET Framework
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
.net framework
Weakness
CWE-209
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news