Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45490

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

A flaw was found in the .NET SDK dotnet.exe workload command on Windows. Insufficient access controls on a named pipe could allow a local attacker to perform arbitrary file creation or truncation operations with the privileges of another local user. This issue may lead to privilege escalation and unauthorized access, modification, or destruction of data belonging to the targeted user.

Отчет

Red Hat products are not affected by this vulnerability. The issue is specific to the .NET SDK workload management functionality on Microsoft Windows systems and does not impact Red Hat supported platforms.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet10.0Not affected
Red Hat Enterprise Linux 10dotnet8.0Not affected
Red Hat Enterprise Linux 10dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet10.0Not affected
Red Hat Enterprise Linux 8dotnet8.0Not affected
Red Hat Enterprise Linux 8dotnet9.0Not affected
Red Hat Enterprise Linux 9dotnet10.0Not affected
Red Hat Enterprise Linux 9dotnet8.0Not affected
Red Hat Enterprise Linux 9dotnet9.0Not affected
Red Hat Hardened Imagesdotnet10.0Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2487184dotnet: .NET SDK workload elevate: arbitrary file creation/truncation via LogFile named pipe.

EPSS

Процентиль: 31%
0.00384
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
nvd
около 2 месяцев назад

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
msrc
около 2 месяцев назад

.NET SDK Elevation of Privilege Vulnerability

CVSS3: 7.8
github
около 2 месяцев назад

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
fstec
около 2 месяцев назад

Уязвимость программной платформы .NET, связанная с ошибками авторизации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 31%
0.00384
Низкий

7.8 High

CVSS3