Описание
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
A flaw was found in the .NET SDK dotnet.exe workload command on Windows. Insufficient access controls on a named pipe could allow a local attacker to perform arbitrary file creation or truncation operations with the privileges of another local user. This issue may lead to privilege escalation and unauthorized access, modification, or destruction of data belonging to the targeted user.
Отчет
Red Hat products are not affected by this vulnerability. The issue is specific to the .NET SDK workload management functionality on Microsoft Windows systems and does not impact Red Hat supported platforms.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet9.0 | Not affected | ||
| Red Hat Hardened Images | dotnet10.0 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Уязвимость программной платформы .NET, связанная с ошибками авторизации, позволяющая нарушителю повысить свои привилегии
EPSS
7.8 High
CVSS3