CVE-2014-4149: Microsoft .NET Framework

High severity, CVSS 9.3. EPSS: 21.4% chance of exploitation in the next 30 days.

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."

Affected products

  • Microsoft .NET Framework: version 1.1 only; version 2.0 only; version 3.5 only; version 3.5.1 only; version 4.0 only; version 4.5 only; …

Published 2014-11-11. Last modified 2026-06-17.