PT-2019-3177 · Microsoft · .Net Framework
Eran Shimony
·
Publicado
2019-09-10
·
Atualizado
2020-08-24
·
CVE-2019-1142
CVSS v2.0
6.0
Média
| Vetor | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework (affected versions not specified)
Description
The issue is related to errors in privilege management, allowing an attacker to elevate their privileges. It is caused by the .NET Framework common language runtime (CLR) permitting file creation in arbitrary locations. An attacker who successfully exploits this could write files to folders that require higher privileges than what the attacker already has. To exploit the issue, an attacker would need to log into a system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
.Net Framework