Executive brief
A security vulnerability in Microsoft .NET could allow a user who already has basic access to a computer to gain higher-level administrative permissions. .NET is a widely used software framework for building and running applications on Windows and other platforms. If exploited, an attacker could take full control of the affected system, potentially accessing sensitive data or disrupting business operations.
Technical details
An improper authorization vulnerability (CWE-285) exists in Microsoft .NET. The flaw allows a locally authenticated attacker with low privileges to bypass authorization checks and elevate their privileges to a higher level, such as SYSTEM or Administrator. The attack requires local access to the target machine but does not require user interaction. According to the CVSS vector, the vulnerability has high impact on confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.
Affected products
- Microsoft .NET
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory