Описание
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
A flaw was found in .NET. This vulnerability allows an unauthorized attacker to disclose sensitive information over a network. The issue arises from the inclusion of functionality from an untrusted control sphere, which can be exploited to reveal data.
Отчет
Red Hat has determined that shipped versions of .NET in Red Hat products already include the fix for this vulnerability. The .NET 8.0 (8.0.30), 9.0 (9.0.19), and 10.0 (10.0.11) runtime fix versions are included in current Red Hat packages. Furthermore, the upstream advisory identifies only Microsoft.WindowsDesktop.App.Runtime (Windows Desktop) packages as vulnerable — a component not present in Red Hat's Linux .NET builds.
Меры по смягчению последствий
No mitigation is needed. All shipped versions of .NET in Red Hat products already contain the fix for this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet11.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet/sdk | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet11.0 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Уязвимость программной платформы Microsoft .NET и средства разработки программного обеспечения Microsoft Visual Studio, связанная с нарушением механизма защиты данных, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
6.5 Medium
CVSS3