CVE Vulnerabilities

CVE-2025-21173

Creation of Temporary File in Directory with Insecure Permissions

Published: Jan 14, 2025 | Modified: May 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.3 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

.NET Elevation of Privilege Vulnerability

Weakness

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.

Affected Software

NameVendorStart VersionEnd Version
Visual_studio_2022Microsoft17.6.0 (including)17.6.22 (excluding)
Visual_studio_2022Microsoft17.8.0 (including)17.8.17 (excluding)
Visual_studio_2022Microsoft17.10.0 (including)17.10.10 (excluding)
Visual_studio_2022Microsoft17.12.0 (including)17.12.4 (excluding)
Red Hat Enterprise Linux 8RedHatdotnet8.0-0:8.0.112-1.el8_10*
Red Hat Enterprise Linux 8RedHatdotnet9.0-0:9.0.102-1.el8_10*
Red Hat Enterprise Linux 9RedHatdotnet8.0-0:8.0.112-1.el9_5*
Red Hat Enterprise Linux 9RedHatdotnet9.0-0:9.0.102-1.el9_5*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatdotnet8.0-0:8.0.112-1.el9_4*
Dotnet6Ubuntujammy*
Dotnet7Ubuntujammy*
Dotnet8Ubuntudevel*
Dotnet8Ubuntujammy*
Dotnet8Ubuntunoble*
Dotnet8Ubuntuoracular*
Dotnet9Ubuntudevel*
Dotnet9Ubuntuoracular*

Potential Mitigations

References