Описание
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
A flaw was found in .NET. This vulnerability, stemming from improper link resolution before file access, allows an authorized local attacker to perform tampering. This could lead to unauthorized modification of data or system files.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2026:41893 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2026:41895 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet10.0 | Fixed | RHSA-2026:41897 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2026:41899 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet10.0 | Fixed | RHSA-2026:41900 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2026:41901 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2026:41894 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet9.0 | Fixed | RHSA-2026:41896 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet10.0 | Fixed | RHSA-2026:41898 | 20.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
Уязвимость программной платформы Microsoft .NET и редактора исходного кода Visual Studio Code, связанная с ошибками обработки символических ссылок, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
7 High
CVSS3