← Back

CVE-2014-4073

nvd nist
Published: Oct 15, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."

Affected (7)

1 product
.net Framework
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2.0 sp2
Version 3.5.1
Version 3.5
Version 4.0
Version 4.5.1
Version 4.5.2
Version 4.5

Related CWEs

Timeline

No history available yet.