CVE-2014-0257: Microsoft .NET Framework
High severity, CVSS 9.3. EPSS: 69.8% chance of exploitation in the next 30 days.
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers to execute arbitrary code via (1) a crafted web site or (2) a crafted .NET Framework application that exposes a COM server endpoint, aka "Type Traversal Vulnerability."
Affected products
- Microsoft .NET Framework: version 1.0 only; version 1.1 only; version 2.0 only; version 3.5 only; version 3.5.1 only; version 4.0 only; …
Published 2014-02-12. Last modified 2026-06-17.