Executive brief
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker. This exposure can be leveraged to facilitate remote code execution. The vulnerability is actively exploited in the wild.
Affected products
- Microsoft .NET Framework 2.0, 3.0, 3.5, 4.6, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1
Timeline
- 2024-11-21: disclosed
- 2025-01-08: other: Initial NIST analysis and CPE assignment
- 2025-02-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-04: advisory: Published date per advisory metadata