Impact
The vulnerability in Microsoft .NET involves improper handling of sensitive data and dynamic code generation, exposing confidential information that can be leveraged to elevate privileges locally. This flaw combines the weaknesses identified by CWE-200 and CWE-94, allowing an authorized user to access data that can be used to acquire higher levels of access. As a result, attackers can gain administrative rights on systems where the affected .NET runtime or Visual Studio is installed.
Affected Systems
Microsoft .NET 9.0, 10.0, and 11.0 as well as Microsoft Visual Studio 2022 version 17.14 and Visual Studio 2026 version 18.9 are impacted by this CVE. The affected versions are those explicitly listed in the vendor product references; no further narrowing of sub‑versions is provided.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high severity, and the EPSS score is 2%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local – it requires an authorized attacker with existing access to the affected environment to exploit the information disclosure and code generation weakness. Once exploited, the attacker can gain full administrative control over the affected system, posing a significant risk to any resources running the impacted .NET components.
OpenCVE Enrichment
Ubuntu USN