PT-2019-3177 · Microsoft · .Net Framework
Eran Shimony
·
Published
2019-09-10
·
Updated
2020-08-24
·
CVE-2019-1142
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework (affected versions not specified)
Description
The issue is related to errors in privilege management, allowing an attacker to elevate their privileges. It is caused by the .NET Framework common language runtime (CLR) permitting file creation in arbitrary locations. An attacker who successfully exploits this could write files to folders that require higher privileges than what the attacker already has. To exploit the issue, an attacker would need to log into a system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
.Net Framework