HIGH
CVE-2024-29059
CVSS
7.5
KEV
Description
.NET Framework Information Disclosure Vulnerability
Summary dbcve.org
An information disclosure vulnerability in .NET Framework allows unauthorized attackers to potentially access sensitive information through improper error handling or configuration. The CVSS 7.5 score indicates high impact on confidentiality without requiring authentication or user interaction.
Mitigation
Review and properly configure customErrors settings in web.config, ensure debug mode is disabled in production environments, and apply available Microsoft security patches for .NET Framework.
Weakness (CWE)
CWE-209
EPSS Score
98.62%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.