.NET Improper Link Resolution Vulnerability Allowing Local Tampering
Vulnerability
A vulnerability exists in .NET due to improper link resolution before file access, commonly referred to as 'link following'. This flaw allows an authorized attacker to manipulate files locally. The issue is present in .NET 8.0, 9.0, and 10.0, across Windows, Mac OS, and Linux platforms, as well as in Microsoft Visual Studio 2022 versions 17.12 and 17.14, and Visual Studio 2026 version 18.7.
Impact
Exploitation of this vulnerability could lead to unauthorized tampering with files or data.
Remediation
Users can download the security update for .NET 8.0, 9.0, and 10.0 from the .NET website. Microsoft Visual Studio users can download the security update from the Visual Studio download center. Specific knowledge base articles are available for each product version to provide additional guidance.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
