Home

Description

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

PUBLISHED Reserved 2026-05-12 | Published 2026-06-09 | Updated 2026-06-10 | Assigner microsoft




MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Problem types

CWE-59: Improper Link Resolution Before File Access ('Link Following')

Product status

10.0.0 (custom) before 10.0.9
affected

8.0 (custom) before 8.0.28
affected

8.0.0 (custom) before 8.0.28
affected

9.0.0 (custom) before 9.0.17
affected

References

msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491 (.NET Tampering Vulnerability) vendor-advisory patch

cve.org (CVE-2026-45491)

nvd.nist.gov (CVE-2026-45491)

Download JSON