PT-2025-1101 · Microsoft+8 · .Net Framework+9

Daniel Plaisted

+1

·

Published

2025-01-14

·

Updated

2025-12-16

·

CVE-2025-21173

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions .NET (affected versions not specified)
Description The issue is related to a privilege elevation problem in the .NET platform, which is also associated with Microsoft Visual Studio. It involves the creation of a temporary file in a directory with incorrect permissions. Exploitation of this issue could allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

ALSA-2025:0381
ALSA-2025:0382
ALT-PU-2025-13074
ALT-PU-2025-13075
ALT-PU-2025-15796
ALT-PU-2025-5283
BDU:2025-00356
BIT-DOTNET-2025-21173
BIT-DOTNET-SDK-2025-21173
CESA-2025_0381
CESA-2025_0382
CVE-2025-21173
INFBA-2025_0304
INFBA-2025_0305
INFSA-2025_0381
INFSA-2025_0382
RHSA-2025:0381
RHSA-2025:0382
RHSA-2025:0532
RHSA-2025_0381
RHSA-2025_0382
RLSA-2025:0381
RLSA-2025:0382
USN-7210-1

Affected Products

.Net Framework
Alt Linux
Almalinux
Centos
Linuxmint
Visual Studio
Red Hat
Red Os
Rocky Linux
Ubuntu