Elevation of Privilege Vulnerability in .NET by Microsoft
CVE-2025-55247
7.3HIGH
What is CVE-2025-55247?
An elevation of privilege vulnerability in .NET arises from improper link resolution before file access, also known as 'link following'. This allows an authorized attacker to gain elevated access privileges locally, potentially leading to unauthorized actions or data exposure. Organizations using affected .NET versions should implement recommended mitigations to protect their systems.
Affected Version(s)
.NET 8.0 8.0.0 < 8.0.21
.NET 9.0 9.0.0 < 9.0.10