Impact
Improper authorization in the .NET SDK enables an attacker with local authorization to elevate privileges. The vulnerability is classified as CWE-285 and allows a user to acquire higher rights on the same machine, potentially compromising confidentiality and integrity of the system.
Affected Systems
The vulnerability affects Microsoft .NET 10.0, Microsoft .NET 8.0, and Microsoft .NET 9.0. No specific sub‑release or patch level is specified in the data available.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity risk. EPSS data is not available, so an exploit probability estimate cannot be provided. The vulnerability is not listed in CISA’s KEV catalog. It is likely that the attacker must already have local legitimate access and then exploit the improper authorization to gain elevated privileges; this attack vector is inferred from the description.
OpenCVE Enrichment