Impact
The vulnerability is an incorrect authorization flaw in the .NET Framework that allows an attacker who already has some level of authorized access to elevate privileges over a network. This flaw is classified as CWE-863 and can result in the attacker gaining higher privileges than intended, potentially compromising the confidentiality, integrity, or availability of the affected system.
Affected Systems
Affected vendors are Microsoft with .NET Framework versions 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1. Systems installed any of these frameworks are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, but the EPSS score is not available, so current exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through network traffic to a system that allows the attacker to send requests that trigger the authorization error, because the flaw allows privilege escalation over a network. This means that an attacker with remote or local authorized access can leverage it to increase their privileges.
OpenCVE Enrichment