Описание
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | windows only |
| focal | DNE | |
| jammy | DNE | |
| noble | not-affected | windows only |
| questing | not-affected | windows only |
| resolute | not-affected | windows only |
| trusty | DNE | |
| upstream | needs-triage | |
| xenial | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| focal | DNE | |
| jammy | not-affected | windows only |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| trusty | DNE | |
| upstream | needs-triage | |
| xenial | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| focal | DNE | |
| jammy | ignored | see notes |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| trusty | DNE | |
| upstream | needs-triage | |
| xenial | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| focal | DNE | |
| jammy | not-affected | windows only |
| noble | not-affected | windows only |
| questing | not-affected | windows only |
| resolute | DNE | |
| trusty | DNE | |
| upstream | needs-triage | |
| xenial | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| focal | DNE | |
| jammy | DNE | |
| noble | DNE | |
| questing | not-affected | windows only |
| resolute | DNE | |
| trusty | DNE | |
| upstream | needs-triage | |
| xenial | DNE |
Показывать по
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
Уязвимость программной платформы .NET Core, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю записать произвольные файлы
EPSS
4.3 Medium
CVSS3