{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-45490",
        "tracking": {
            "current_release_date": "2026-06-10T18:56:34.462232Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-45490",
            "initial_release_date": "2026-06-09T08:20:49.004785Z",
            "revision_history": [
                {
                    "date": "2026-06-09T08:20:49.004785Z",
                    "number": "1",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-06-09T17:32:40.782803Z",
                    "number": "2",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-06-09T17:32:43.032767Z",
                    "number": "3",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-09T17:50:06.062753Z",
                    "number": "4",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-06-09T17:50:08.418322Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-09T17:53:08.248906Z",
                    "number": "6",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| Product Identifiers created (3).| Product Threats created (6).| Product Remediations created (3).| CWES updated (1).| Exploitable created."
                },
                {
                    "date": "2026-06-09T18:04:55.323349Z",
                    "number": "7",
                    "summary": "Source connected.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-06-09T18:05:01.736470Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-09T18:30:12.571904Z",
                    "number": "9",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2026-06-10T05:40:07.471500Z",
                    "number": "10",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-06-10T15:18:24.016462Z",
                    "number": "11",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-06-10T15:18:28.654418Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-10T16:04:52.256164Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-06-10T18:56:29.730915Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (15).| Product Identifiers created (14).| References created (5)."
                },
                {
                    "date": "2026-06-10T18:56:32.648907Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "15"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.0.0|<10.0.9",
                                "product": {
                                    "name": "vers:unknown/10.0.0|<10.0.9",
                                    "product_id": "CSAFPID-8257140"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": ".NET 10.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/10.0.0",
                                        "product": {
                                            "name": "vers:microsoft/10.0.0",
                                            "product_id": "CSAFPID-5590018",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:.net:10.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": ".NET 10.0 installed on Windows"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/8.0.0",
                                        "product": {
                                            "name": "vers:microsoft/8.0.0",
                                            "product_id": "CSAFPID-1519978",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:.net:8.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": ".NET 8.0 installed on Windows"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/9.0.0",
                                        "product": {
                                            "name": "vers:microsoft/9.0.0",
                                            "product_id": "CSAFPID-1441528",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:.net:9.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": ".NET 9.0 installed on Windows"
                            }
                        ],
                        "category": "product_family",
                        "name": "Developer Tools"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.0|<8.0.28",
                                "product": {
                                    "name": "vers:unknown/8.0.0|<8.0.28",
                                    "product_id": "CSAFPID-8257141"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": ".NET 8.0"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.0|<9.0.17",
                                "product": {
                                    "name": "vers:unknown/9.0.0|<9.0.17",
                                    "product_id": "CSAFPID-8257142"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": ".NET 9.0"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.105-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.105-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854866",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.105-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.107-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.107-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854867",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.107-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.108-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.108-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854868",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.108-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.109-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.109-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854869",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.109-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.110-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.110-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854870",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.110-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.111-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.111-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854871",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.111-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.112-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.112-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854872",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.112-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.113-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.113-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854873",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.113-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.114-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.114-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854874",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.114-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.115-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.115-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854875",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.115-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.116-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.116-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854876",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.116-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.117-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.117-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854877",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.117-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.117-0ubuntu1~22.04.2",
                                        "product": {
                                            "name": "vers:unknown/7.0.117-0ubuntu1~22.04.2",
                                            "product_id": "CSAFPID-3854878",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.117-0ubuntu1~22.04.2?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.119-0ubuntu1~22.04.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.119-0ubuntu1~22.04.1",
                                            "product_id": "CSAFPID-3854879",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/dotnet7@7.0.119-0ubuntu1~22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3854880"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "dotnet7"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:22.04:LTS"
                    }
                ],
                "category": "vendor",
                "name": "Ubuntu"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-45490",
            "notes": [
                {
                    "category": "description",
                    "text": "Improper authorization in .NET allows an authorized attacker to elevate privileges locally.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-45490"
                },
                {
                    "category": "description",
                    "text": "Improper authorization in .NET allows an authorized attacker to elevate privileges locally.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45490.json"
                },
                {
                    "category": "description",
                    "text": "<p>Improper authorization in .NET allows an authorized attacker to elevate privileges locally.</p>\n",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jun"
                },
                {
                    "category": "description",
                    "text": "Improper authorization in .NET allows an authorized attacker to elevate privileges locally.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-45490.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00055",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "6.0",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "VENDOR FIX as product remediation category, IMPACT as product threat category, There is news data available from source Bleepingcomputer",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-8257140",
                    "CSAFPID-8257141",
                    "CSAFPID-8257142",
                    "CSAFPID-1441528",
                    "CSAFPID-1519978",
                    "CSAFPID-5590018",
                    "CSAFPID-3854866",
                    "CSAFPID-3854867",
                    "CSAFPID-3854868",
                    "CSAFPID-3854869",
                    "CSAFPID-3854870",
                    "CSAFPID-3854871",
                    "CSAFPID-3854872",
                    "CSAFPID-3854873",
                    "CSAFPID-3854874",
                    "CSAFPID-3854875",
                    "CSAFPID-3854876",
                    "CSAFPID-3854877",
                    "CSAFPID-3854878",
                    "CSAFPID-3854879",
                    "CSAFPID-3854880"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-45490"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45490.json"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jun"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0184"
                },
                {
                    "category": "external",
                    "summary": "Source - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-45490.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "News - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/"
                },
                {
                    "category": "external",
                    "summary": "News - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://ubuntu.com/security/CVE-2026-45490"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-45490"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-june-2026-servicing-updates"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/dotnet/announcements/issues/403"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "5097150",
                    "product_ids": [
                        "CSAFPID-1441528"
                    ],
                    "url": "https://dotnet.microsoft.com/download/dotnet/9.0"
                },
                {
                    "category": "vendor_fix",
                    "details": "5097149",
                    "product_ids": [
                        "CSAFPID-1519978"
                    ],
                    "url": "https://dotnet.microsoft.com/download/dotnet/8.0"
                },
                {
                    "category": "vendor_fix",
                    "details": "5097148",
                    "product_ids": [
                        "CSAFPID-5590018"
                    ],
                    "url": "https://dotnet.microsoft.com/download/dotnet/10.0"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1441528",
                        "CSAFPID-1519978",
                        "CSAFPID-3854866",
                        "CSAFPID-3854867",
                        "CSAFPID-3854868",
                        "CSAFPID-3854869",
                        "CSAFPID-3854870",
                        "CSAFPID-3854871",
                        "CSAFPID-3854872",
                        "CSAFPID-3854873",
                        "CSAFPID-3854874",
                        "CSAFPID-3854875",
                        "CSAFPID-3854876",
                        "CSAFPID-3854877",
                        "CSAFPID-3854878",
                        "CSAFPID-3854879",
                        "CSAFPID-3854880",
                        "CSAFPID-5590018",
                        "CSAFPID-8257140",
                        "CSAFPID-8257141",
                        "CSAFPID-8257142"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "exploit_status",
                    "details": "Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely",
                    "product_ids": [
                        "CSAFPID-1441528",
                        "CSAFPID-1519978",
                        "CSAFPID-5590018"
                    ]
                },
                {
                    "category": "impact",
                    "details": "Elevation of Privilege",
                    "product_ids": [
                        "CSAFPID-1441528",
                        "CSAFPID-1519978",
                        "CSAFPID-5590018"
                    ]
                },
                {
                    "category": "exploit_status",
                    "details": "exploited"
                }
            ],
            "title": "CVE-2026-45490"
        }
    ]
}