Jump to content

.NET Desktop Runtime 6 - Remote Code Execution and Privilege Escalation


Recommended Posts

Posted

1) Does Nexus Mods: Vortex seriously require .NET Desktop Runtime 6.x.x

2) Do people know that this requirement exposes them to already patched critical vulnerabilities? 

  • Even the last version (most recent) 6.0.36 is vulnerable to weak privilege escalation. 
  • .NET Desktop Runtime 6 (SDK, etc) are all END OF LIFE, and UNSUPPORTED
  • For a widespread, commonly used, highly popular application such as Vortex, I find this concerning. 

3) What reasoning is there behind the failure to upgrade to a supported version? What technical specifics are "incompatible" with newer versions?

4) Is this acceptable for "Lifetime" premium membership accounts (an END OF LIFE requirement)? To accept major security flaws and install them on their daily-driver PC? 

5) Are there instructions for running Vortex in a Sandbox? 

CDN media

 

Quote

https://devblogs.microsoft.com/dotnet/dotnet-6-end-of-support/
Using .NET 6 apps
If you’re using a .NET 6 app, we recommend reaching out to the software developer or vendor who produced it to ask if an updated version that uses .NET 8 is available.

Quote

NEXUS VORTEX INSTALLATION ERROR WINDOW (NON-SELECTABLE TEXT) [TRANSCRIBED AND SCREENSHOT ATTACHED]: 

Check failed

Vortex requires .NET Desktop Runtime 6 to be installed even though you may already have a newer version. This is due to incompatible changes in the more recent versions.

If you already have .NET Desktop Runtime 6 installed then there may be a problem with your installation and a reinstall might be needed.

Click "Fix" below to install the required version.

Show detailed error

You must install or update .NET to run this application.
App: C:\Program Files\Black Tree Gaming Ltd\Vortex\resources\app.asar.unpacked\assets\dotnetprobe.exe
Architecture: x64
Framework: Microsoft.NETCore.App, version 6.0.0 (x64)
.NET location: C:\Program Files\dotnet
The following frameworks were found: 8.0.18 at C:\Program Files\dotnet\shared\Microsoft.NETCore.App
Learn more: https://aka.ms/dotnet/app-launch-failed
To install missing framework, download:
https://aka.ms/dotnet-core-applaunch?framework=Microsoft.NETCore.App&framework_version=6.0.0&arch=x64&rid=win-x64&os=win10

[Quit Vortex] [Fix]

image.png.e038d60c580b489b2bbd4e2b129ea954.png

Other information [EXPLOITATION]: 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...