Impact
Integer overflow or wraparound in the .NET runtime allows an attacker who can execute code locally to gain higher privileges than intended. The flaw falls under CWE‑190, which involves incorrect integer arithmetic leading to security violations. As a result, a local attacker could increase their privilege level, potentially accessing or modifying protected resources on the affected system.
Affected Systems
The vulnerability affects Microsoft .NET 8.0, 9.0, and 10.0. All applications that run on these runtime versions are potentially impacted, including server‑side services, desktop applications, and background processes that rely on the .NET framework.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity. Because the flaw is local, an attacker would need access to the machine to exploit it, but once on the system the impact is significant. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no widely known exploits yet. Nonetheless, the potential for privilege escalation warrants prompt remediation.
OpenCVE Enrichment