CVE-2014-1806
published 2014-05-14CVE-2014-1806: The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which…
PriorityP272critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
39.59%
98.5th percentile
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for .NET Remoting TCP traffic on non-standard ports matching the pattern tcp://host:port/ObjName, which is the URI format used by the exploit tool to reach vulnerable remoting endpoints. ↗
- →Monitor for Named Pipe connections matching the IPC channel URI format ipc://channel/ObjName, which the exploit tool uses to target local IPC-based .NET Remoting services. ↗
- →Look for use of the --usecom flag (DCOM backchannel) in process command lines or network artifacts; this variant bypasses the primary CVE-2014-1806 patch and works remotely when COM configuration is modified and the firewall is disabled. ↗
- →Detect --useser (old serialization tricks) usage targeting .NET Remoting services running with full TypeFilterLevel mode; this variant enables file listing, upload, and download against fully-trusted remoting endpoints. ↗
- →Audit .NET Remoting service registrations via RemotingConfiguration.RegisterWellKnownServiceType and Activator.CreateInstance calls to enumerate exposed attack surface targeted by this exploit. ↗
- →Alert on unexpected file uploads or downloads to/from .NET Remoting service host processes, corresponding to the exploit's 'put' and 'get' commands. ↗
- ·The --useser serialization exploit variant only works against .NET Remoting services configured with full TypeFilterLevel mode enabled; services using lower filter levels are not vulnerable to this specific variant. ↗
- ·The --usecom DCOM backchannel variant works best locally; remote exploitation requires modifying COM configuration and disabling the host firewall. ↗
- ·The exploit tool only runs on Windows; *nix (Mono) support is partial and not guaranteed. ↗
- ·The --useser variant is limited to the ls, put, and get commands only; exec and cmd are not available through this serialization path. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat4.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xm9-p5v4-94q8: The
ghsa_unreviewed·2022-05-14
CVE-2014-1806 [HIGH] CWE-94 GHSA-9xm9-p5v4-94q8: The
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."
Red Hat
samba: no access check verification on stream files
vendor_redhat·2013-10-25·CVSS 4.0
CVE-2013-4475 [MEDIUM] samba: no access check verification on stream files
samba: no access check verification on stream files
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).
Statement: This issue did not affect the samba package in Red Hat Enterprise Linux 5. This issue was addressed for the samba3x package in Red Hat Enterprise Linux 5 and the samba package in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2013-1806.html, and the samba package in Red Hat Storage via https://rhn.redhat.com/errata/RHSA-2014-0009.html
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat
No detection rules found.
Talos
Microsoft Update Tuesday May 2014: relatively light month
blogs_talos·2014-05-13·CVSS 4.3
[MEDIUM] Microsoft Update Tuesday May 2014: relatively light month
## Microsoft Update Tuesday May 2014: relatively light month
It’s time for another Microsoft Update Tuesday , the first one which will not feature any XP updates (except of course for the out-of-band patch ( MS14-021 ) which was released to deal with the IE 0-day which is officially part of this release, but which we won't be discussing here, more on that can be found here and here ). It’s a pretty straightforward month this time around, with eight bulletins covering 13 CVEs.
The numbering is a little off this month, usually the critical bulletins came first, but it seems that Microsoft hasn't done that this time around. We’ll list the critical bulletins first, followed by the important ones.
There’s two critical bulletins and six important bulletins this month:
The first critical bull
Talos
Microsoft Update Tuesday May 2014: relatively light month
blogs_talos·2014-05-13·CVSS 4.3
[MEDIUM] Microsoft Update Tuesday May 2014: relatively light month
It’s time for another Microsoft Update Tuesday, the first one which will not feature any XP updates (except of course for the out-of-band patch (MS14-021) which was released to deal with the IE 0-day which is officially part of this release, but which we won't be discussing here, more on that can be found here and here). It’s a pretty straightforward month this time around, with eight bulletins covering 13 CVEs.
The numbering is a little off this month, usually the critical bulletins came first, but it seems that Microsoft hasn't done that this time around. We’ll list the critical bulletins first, followed by the important ones.
There’s two critical bulletins and six important bulletins this month:
The first critical bulletin is MS14-022 and covers three CVEs in Sharepoint. Two of them
2014-05-14
Published