
Find real vulnerabilities before they ship
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
Base Score
4.3| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Microsoft.NetCore.App.Runtime.win-arm(NuGet) | 8.0.0 | 8.0.27 | N/A |
| Microsoft.NetCore.App.Runtime.win-arm(NuGet) | 9.0.0 | 9.0.16 | N/A |
| Microsoft.NetCore.App.Runtime.win-arm(NuGet) | 10.0.0 | 10.0.8 | N/A |
| Microsoft.NetCore.App.Runtime.win-arm64(NuGet) | 8.0.0 | 8.0.27 | N/A |
| Microsoft.NetCore.App.Runtime.win-arm64(NuGet) | 9.0.0 | 9.0.16 | N/A |
| Microsoft.NetCore.App.Runtime.win-arm64(NuGet) | 10.0.0 | 10.0.8 | N/A |
| Microsoft.NetCore.App.Runtime.win-x64(NuGet) | 8.0.0 | 8.0.27 | N/A |
| Microsoft.NetCore.App.Runtime.win-x64(NuGet) | 9.0.0 | 9.0.16 | N/A |
| Microsoft.NetCore.App.Runtime.win-x64(NuGet) | 10.0.0 | 10.0.8 | N/A |
| Microsoft.NetCore.App.Runtime.win-x86(NuGet) | 8.0.0 | 8.0.27 | N/A |
| Microsoft.NetCore.App.Runtime.win-x86(NuGet) | 9.0.0 | 9.0.16 | N/A |
| Microsoft.NetCore.App.Runtime.win-x86(NuGet) | 10.0.0 | 10.0.8 | N/A |
| Base Score | 4.3 |
|---|---|
| Vector String | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| Base Severity | Medium |
| Version | 3.1 |
| Attack Vector (AV) | NETWORK |