Impact
An uncaught exception in the .NET runtime allows an authenticated local user to trigger a privilege escalation that grants elevated system rights, thereby enabling unauthorized code execution and compromising confidentiality, integrity, and availability. The vulnerability is classified as CWE‑252, indicating a missing exception assertion that permits an attacker to bypass intended control flow.
Affected Systems
The affected components are Microsoft .NET Framework versions 8.0, 9.0, and 10.0, as well as Microsoft Visual Studio 2022 version 17.14 and Visual Studio 2026 version 18.8, all of which are widely deployed in development and runtime environments.
Risk and Exploitability
The flaw carries a CVSS score of 7.8, placing it in the high severity category. No EPSS data is available, but the lack of a low exploitation probability suggests that organizations should prioritize remediation. It is not listed in the CISA KEV catalog; however, local privilege escalation is a significant threat on any system running the affected runtime. The likely attack vector is local, requiring an authenticated user to trigger the exception within a privileged context.
OpenCVE Enrichment
Github GHSA