.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
.net_framework | Microsoft | 4.6.2 (including) | 4.6.2 (including) |
.net_framework | Microsoft | 4.7 (including) | 4.7 (including) |
.net_framework | Microsoft | 4.7.1 (including) | 4.7.1 (including) |
.net_framework | Microsoft | 4.7.2 (including) | 4.7.2 (including) |
Dotnet6 | Ubuntu | upstream | * |
Dotnet7 | Ubuntu | jammy | * |
Dotnet7 | Ubuntu | mantic | * |
Dotnet8 | Ubuntu | upstream | * |