Описание
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
A flaw was found in .NET Framework. This vulnerability, caused by a relative path traversal, allows an unauthorized local attacker to elevate their privileges. By exploiting this flaw, an attacker can gain higher access rights than intended, potentially leading to unauthorized actions on the system.
Отчет
Red Hat ships cross-platform .NET runtimes (dotnet 8.0, 9.0, 10.0) on Linux. The .NET Framework runtime affected by this vulnerability is a Windows-only product distributed via Windows Update, which Red Hat has never shipped. The vulnerable code is not present in any Red Hat product.
Меры по смягчению последствий
No mitigation is required. Red Hat does not ship the Windows-only .NET Framework runtime.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet11.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet8.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet9.0 | Not affected | ||
| Red Hat Enterprise Linux 8 | dotnet/sdk | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet11.0 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Уязвимость программной платформы Microsoft .NET Framework, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю повысить свои привилегии
7.8 High
CVSS3