Improper link resolution before file access (link following) in .NET allows an authorized attacker to elevate privileges locally.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| .net | Microsoft | 8.0.0 (including) | 8.0.21 (excluding) |
| .net | Microsoft | 9.0.0 (including) | 9.0.10 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | dotnet8.0-0:8.0.121-1.el10_0 | * |
| Red Hat Enterprise Linux 10 | RedHat | dotnet9.0-0:9.0.111-1.el10_0 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet8.0-0:8.0.121-1.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet9.0-0:9.0.111-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet8.0-0:8.0.121-1.el9_6 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet9.0-0:9.0.111-1.el9_6 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | dotnet8.0-0:8.0.121-1.el9_4 | * |
| Dotnet10 | Ubuntu | devel | * |
| Dotnet10 | Ubuntu | questing | * |
| Dotnet7 | Ubuntu | jammy | * |
| Dotnet8 | Ubuntu | devel | * |
| Dotnet8 | Ubuntu | jammy | * |
| Dotnet8 | Ubuntu | noble | * |
| Dotnet8 | Ubuntu | plucky | * |
| Dotnet8 | Ubuntu | questing | * |
| Dotnet9 | Ubuntu | devel | * |
| Dotnet9 | Ubuntu | plucky | * |
| Dotnet9 | Ubuntu | questing | * |