Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation requires a Linux environment where users share a process identifier namespace and process information is exposed to other local users through the proc filesystem. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain the privileges of the user account or service account running the affected process.
<a href="https://x.com/ky0tofu">Ky0toFu</a>, <a href="https://www.linkedin.com/in/rajeshchada/">Rajesh Chada</a> with Microsoft