.NET Elevation of Privilege Issue Affecting Microsoft Products
CVE-2025-21173
7.3HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 14 January 2025
Summary
This vulnerability in the .NET Framework allows an attacker to execute code with elevated privileges, potentially allowing unauthorized access to system resources. Implementing security best practices and promptly applying updates can help mitigate the associated risks. For more details, refer to the official advisory.
Affected Version(s)
.NET 8.0 Unknown 8.0.0 < 8.0.12
.NET 9.0 Unknown 9.0.0 < 9.0.1
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.10
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved