Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2014-4149

Description

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."

POC

Reference

No PoCs from references.

Github

- https://github.com/alphaSeclab/sec-daily-2019

- https://github.com/emtee40/ExploitRemotingService

- https://github.com/jezzus/ExploitRemotingService

- https://github.com/likekabin/ExploitRemotingService

- https://github.com/likescam/ExploitRemotingService

- https://github.com/parteeksingh005/ExploitRemotingService_Compiled

- https://github.com/theralfbrown/ExploitRemotingService-binaries

- https://github.com/tyranid/ExploitRemotingService