CVE Vulnerabilities

CVE-2025-21173

Creation of Temporary File in Directory with Insecure Permissions

Published: Jan 14, 2025 | Modified: Feb 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.3 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

.NET Elevation of Privilege Vulnerability

Weakness

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.

Affected Software

Name Vendor Start Version End Version
Visual_studio_2022 Microsoft 17.6.0 (including) 17.6.22 (excluding)
Visual_studio_2022 Microsoft 17.8.0 (including) 17.8.17 (excluding)
Visual_studio_2022 Microsoft 17.10.0 (including) 17.10.10 (excluding)
Visual_studio_2022 Microsoft 17.12.0 (including) 17.12.4 (excluding)
Red Hat Enterprise Linux 8 RedHat dotnet8.0-0:8.0.112-1.el8_10 *
Red Hat Enterprise Linux 8 RedHat dotnet9.0-0:9.0.102-1.el8_10 *
Red Hat Enterprise Linux 9 RedHat dotnet8.0-0:8.0.112-1.el9_5 *
Red Hat Enterprise Linux 9 RedHat dotnet9.0-0:9.0.102-1.el9_5 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat dotnet8.0-0:8.0.112-1.el9_4 *
Dotnet6 Ubuntu jammy *
Dotnet7 Ubuntu jammy *
Dotnet8 Ubuntu devel *
Dotnet8 Ubuntu jammy *
Dotnet8 Ubuntu noble *
Dotnet8 Ubuntu oracular *
Dotnet9 Ubuntu devel *
Dotnet9 Ubuntu oracular *

Potential Mitigations

References