HIGH

CVE-2024-29059

Microsoft .net Framework 2024-03-23 CVSS v3.1
CVSS
7.5
KEV

Description

.NET Framework Information Disclosure Vulnerability

Summary dbcve.org

An information disclosure vulnerability in .NET Framework allows unauthorized attackers to potentially access sensitive information through improper error handling or configuration. The CVSS 7.5 score indicates high impact on confidentiality without requiring authentication or user interaction.

Mitigation

Review and properly configure customErrors settings in web.config, ensure debug mode is disabled in production environments, and apply available Microsoft security patches for .NET Framework.

Weakness (CWE)

CWE-209

EPSS Score

98.62%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE