CVE-2014-4073: Microsoft .NET Framework

High severity, CVSS 10.0. EPSS: 23.4% chance of exploitation in the next 30 days.

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."

Affected products

  • Microsoft .NET Framework: version 2.0 only; version 3.5 only; version 3.5.1 only; version 4.0 only; version 4.5 only; version 4.5.1 only; …

Published 2014-10-15. Last modified 2026-06-17.