Elevation of Privilege Vulnerability in .NET by Microsoft
CVE-2025-55247

7.3HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 October 2025

What is CVE-2025-55247?

An elevation of privilege vulnerability in .NET arises from improper link resolution before file access, also known as 'link following'. This allows an authorized attacker to gain elevated access privileges locally, potentially leading to unauthorized actions or data exposure. Organizations using affected .NET versions should implement recommended mitigations to protect their systems.

Affected Version(s)

.NET 8.0 8.0.0 < 8.0.21

.NET 9.0 9.0.0 < 9.0.10

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.