Elevation of Privilege Vulnerability in .NET Framework by Microsoft
CVE-2019-1142
5.5MEDIUM
Key Information:
Summary
A vulnerability exists in the .NET Framework's common language runtime (CLR) that allows an attacker to create files in arbitrary locations on the file system. This issue can enable an attacker to elevate their privileges and carry out unauthorized tasks that compromise the system's integrity. It's crucial for users of the affected .NET Framework versions to apply the necessary security updates to mitigate this risk effectively.
Affected Version(s)
Microsoft .NET Framework 3.5 Windows Server 2012
Microsoft .NET Framework 3.5 Windows Server 2012 (Server Core installation)
Microsoft .NET Framework 3.5 Windows 8.1 for 32-bit systems
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved