LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-29059: Microsoft .NET Framework Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 4, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 25, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-29059 to its Known Exploited Vulnerabilities catalog on Feb 4, 2025, with a federal patch deadline of Feb 25, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

CVE-2024-29059 is an information disclosure vulnerability in Microsoft .NET Framework. It can expose an ObjRef URI to an attacker, which CISA notes may ultimately enable remote code execution. For IT and security teams, this matters because .NET Framework is widely deployed on Windows servers and workstations that host business applications, web services, and internal tools; successful abuse could give an attacker a foothold for further compromise. Confirm all version, configuration, and patch details against the official Microsoft advisory before acting.

How it works

The weakness is classified as CWE-209, which covers information exposure that can leak sensitive details an attacker should not see. In this case, the vulnerability allows disclosure of an ObjRef URI. An ObjRef is a .NET remoting construct that identifies a remote object; once an attacker obtains that URI, they may be able to interact with the object in ways that escalate to remote code execution. Exact exploitation steps, required privileges, or network conditions are not provided in the public summary, so treat the issue as an information-leak primitive that can chain into code execution and verify the precise attack surface against the vendor advisory. No public details indicate that ransomware groups have used this CVE.

Am I affected? How to find it in your systems

Microsoft .NET Framework is commonly installed on Windows Server and client systems that run ASP.NET applications, desktop software, services, or remoting endpoints. Inventory every Windows host for the presence of .NET Framework runtimes and any applications that rely on .NET remoting or related serialization features.

How to remediate

The primary remediation is to apply the vendor-supplied update for Microsoft .NET Framework that addresses CVE-2024-29059. Follow Microsoft’s published instructions exactly; CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the update can be applied, reduce exposure with compensating controls that limit an attacker’s ability to reach the vulnerable component or to use a leaked ObjRef.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to broader compromise and data exposure. If you have reason to believe systems were targeted before patching, treat the incident as a potential breach: isolate affected hosts, preserve logs, and begin forensic review. As a quick personal check, you can run a free exposure scan of your email address against known breach data to see whether credentials or other information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · .NET Framework
WeaknessCWE-209
Added to CISA KEVFeb 4, 2025
Federal patch deadlineFeb 25, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities