CVE-2019-1142
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
Affected (9)
Products: Microsoft: .net Framework
Configuration A
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6.1 |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1607 |
Microsoft Windows 8.1 | All versions |
Microsoft Windows Server 2012 | All versions |
Microsoft Windows Server 2016 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | Version 1809 |
Microsoft Windows Server 2016 | Version 1903 |
Microsoft Windows Server 2019 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.5.2 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2012 | All versions |
References (2)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.