CVE-2024-29059This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
Microsoft
.NET Framework
See vendor advisoryThis vulnerability was identified in .NET Framework by Microsoft. Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
Medium - Publicly disclosed
Complete system compromise possible
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29059 ; https://nvd.nist.gov/vuln/detail/CVE-2024-29059
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due Date: 2/25/2025