Описание
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
A flaw was found in dotnet. Improper input validation and an integer overflow in .NET allow an unauthenticated attacker to elevate privileges locally.
Отчет
As this flaw allows an unauthenticated attacker to elevate privileges locally, it has been rated with an important severity. This vulnerability affects .NET running on Windows systems. Therefore, Red Hat products are not affected by this issue.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet9.0 | Not affected | ||
| Red Hat Hardened Images | dotnet10.0 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
Уязвимость программной платформы .NET, связанная с недостаточной проверкой выходных данных, позволяющая нарушителю повысить свои привилегии
7.3 High
CVSS3