Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Microsoft.Build.Tasks.Core(NuGet) | 17.15.0-preview-25277-114 | 18.0.0-preview-25476-107 | N/A |
| Microsoft.Build.Tasks.Core(NuGet) | 17.14.0 | 17.14.28 | N/A |
| Microsoft.Build.Tasks.Core(NuGet) | 17.12.0 | 17.12.50 | N/A |
| Microsoft.Build.Tasks.Core(NuGet) | 17.11.0 | 17.11.48 | N/A |
| Microsoft.Build.Tasks.Core(NuGet) | 17.10.0 | 17.10.46 | N/A |
| Microsoft.Build.Tasks.Core(NuGet) | 17.8.0 | 17.8.43 | N/A |
| Microsoft.Build(NuGet) | 17.15.0-preview-25277-114 | 18.0.0-preview-25476-107 | N/A |
| Microsoft.Build(NuGet) | 17.14.0 | 17.14.28 | N/A |
| Microsoft.Build(NuGet) | 17.12.0 | 17.12.50 | N/A |
| Microsoft.Build(NuGet) | 17.11.0 | 17.11.48 | N/A |
| Microsoft.Build(NuGet) | 17.10.0 | 17.10.46 | N/A |
| Microsoft.Build(NuGet) | 17.8.0 | 17.8.43 | N/A |
| Microsoft.Build.Utilities.Core(NuGet) | 17.15.0-preview-25277-114 | 18.0.0-preview-25476-107 | N/A |
| Microsoft.Build.Utilities.Core(NuGet) | 17.14.0 | 17.14.28 | N/A |
| Microsoft.Build.Utilities.Core(NuGet) | 17.12.0 | 17.12.50 | N/A |
| Microsoft.Build.Utilities.Core(NuGet) | 17.11.0 | 17.11.48 | N/A |
| Microsoft.Build.Utilities.Core(NuGet) | 17.10.0 | 17.10.46 | N/A |
| Microsoft.Build.Utilities.Core(NuGet) | 17.8.0 | 17.8.43 | N/A |
CVSS Metrics