Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."
2014-11-11T22:55:04.857
2025-04-12T10:46:40.837
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | .net_framework | 1.1 | Yes |
Application | microsoft | .net_framework | 2.0 | Yes |
Application | microsoft | .net_framework | 3.5 | Yes |
Application | microsoft | .net_framework | 3.5.1 | Yes |
Application | microsoft | .net_framework | 4.0 | Yes |
Application | microsoft | .net_framework | 4.5 | Yes |
Application | microsoft | .net_framework | 4.5.1 | Yes |
Application | microsoft | .net_framework | 4.5.2 | Yes |