S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jun 10, 2024

CVE-2024-29059 Scanner

CVE-2024-29059 scanner - Information Disclosure vulnerability in .NET Framework

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
1
Times Used
by S4E users
1
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-29059
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft .NET Framework 4.8by Microsoft
AFFECTED< 4.8.04690.02SAFE ✓≥ 4.8.04690.02
Microsoft .NET Framework 3.5 AND 4.8by Microsoft
AFFECTED< 4.8.04690.02SAFE ✓≥ 4.8.04690.02
Microsoft .NET Framework 3.5 AND 4.7.2by Microsoft
AFFECTED< 4.7.04081.03SAFE ✓≥ 4.7.04081.03
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2by Microsoft
AFFECTED< 4.7.04081.03SAFE ✓≥ 4.7.04081.03
Updated Aug 19, 2026View on NVD →
Detail

.NET Framework is a software development platform developed by Microsoft. It is widely used for building and running applications on Windows. Developers use it to create web, desktop, and mobile applications. Businesses and enterprises rely on .NET Framework for building scalable and robust software solutions. It is an essential component in many enterprise environments for its support of multiple programming languages and libraries.

The Information Disclosure vulnerability in .NET Framework allows attackers to leak sensitive information. This can be exploited via HTTP .NET Remoting. The vulnerability is classified as high severity due to its potential impact. Exploitation can lead to unauthorized access to confidential data.

The vulnerability exists in the .NET Remoting service of the .NET Framework. Attackers can exploit it by sending specially crafted HTTP requests. The vulnerable endpoint is "/RemoteApplicationMetadata.rem" which leaks ObjRefs. By leveraging these ObjRefs, attackers can gain access to sensitive data. The vulnerability allows attackers to manipulate the ObjRef and retrieve unauthorized information.

If exploited, this vulnerability can lead to unauthorized access to sensitive information. Attackers can potentially gain insights into the internal workings of the application. This can be used for further attacks or information gathering. The leaked data can include configuration details, internal network information, and potentially user data.

By using the S4E platform, you can protect your digital assets from a wide range of cyber threats. Our comprehensive scanning service helps you identify vulnerabilities like Information Disclosure in the .NET Framework. Stay ahead of potential threats with our regular security checks and detailed reports. Join our platform to enhance your cybersecurity posture and safeguard your business. Benefit from our user-friendly interface and expert support to manage and mitigate risks effectively.

References:

Solution Advice
  • Disable or restrict the use of .NET Remoting if not necessary.
  • Apply the latest security patches and updates provided by Microsoft.
  • Implement network segmentation to limit exposure to critical services.
  • Monitor and log suspicious activities around the .NET Remoting service.
  • Conduct regular security assessments to identify and mitigate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.