Impact
A relative path traversal flaw exists within the .NET Framework, enabling an unauthorized local attacker to write or read files outside the intended scope and ultimately elevate execution privileges. Exploitation can allow the attacker to gain higher-level permissions on the affected machine, compromising confidentiality, integrity, or availability of data and services.
Affected Systems
Microsoft .NET Framework versions from 3.5 through 4.8.1—including the 4.6.2/4.7/4.7.1/4.7.2 and 4.8/4.8.1 releases—are impacted by this flaw due to their shared path handling implementation.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attacker requires local access to the system, making the attack vector local. Exploitation relies on the ability to craft a malicious path that bypasses normal access checks. Without an applied fix, any user with read/write permissions to the system may be able to trigger privilege escalation.
OpenCVE Enrichment