Описание
ASP.NET Elevation of Privilege Vulnerability
FAQ
What privileges could be gained by an attacker who successfully exploited the vulnerability?
The attacker would gain the rights of the user that is running the affected application.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
The target environment could be accidentally configured to allow the vulnerability.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 | ||
| Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation) | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation) | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 R2 | ||
| Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems | ||
| Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems | ||
| Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems | ||
| Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems |
Показывать по
10
Возможность эксплуатации
Publicly Disclosed
No
Exploited
No
Latest Software Release
Exploitation Less Likely
DOS
N/A
EPSS
Процентиль: 99%
0.71915
Высокий
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
fstec
больше 2 лет назад
Уязвимость программной платформы Microsoft .NET Framework, связанная с недостаточной проверкой входных данных, позволяющая нарушителю повысить свои привилегии
EPSS
Процентиль: 99%
0.71915
Высокий
8.8 High
CVSS3