| Description |
FortiGuard Labs have observed active exploration of CVE-2024-29059 in Microsoft .NET Framework.
CVE-2024-29059 is an information disclosure vulnerability in Microsoft .NET Framework which exposes the ObjRef URI to an attacker which could lead to remote code execution. |
||||||
|
CVE ID |
CVE-2024-29059 (https://nvd.nist.gov/vuln/detail/ CVE-2024-29059) |
||||||
|
NDR Cloud Detection Rule |
FortiNDR Cloud v25.1.e+
|
||||||
|
Playbook |
N/A |
||||||
|
Threat Hunting |
FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “Microsoft .NET Framework Information Disclosure” related activities.
IOC source: https://www.fortiguard.com/outbreak-ioc?tag=microsoft%20net%20framework%20information%20disclosure
|
||||||
|
Suricata Coverage |
Customers can create custom investigation/detections using the Suricata signatures below: 2056203 -> ET MALWARE Magnet Goblin Linux Nerbian RAT Trigger Sequence from CnC Server 2056204 -> ET EXPLOIT .NET Remoting SoapServerFormatterSink ObjRef Leak (CVE-2024-29059) |
||||||
|
Other Fortinet Products |
For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.