Relative Path Traversal in .NET Framework by Microsoft
CVE-2026-65810

7.8HIGH

What is CVE-2026-65810?

A vulnerability in the .NET Framework enables unauthorized attackers to leverage relative path traversal techniques to gain elevated privileges on affected systems. This may allow attackers to execute malicious actions that compromise the integrity and confidentiality of the application and its data. It is crucial for users to stay updated with patches provided by Microsoft to mitigate the risks associated with this vulnerability.

Affected Version(s)

Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Windows 10 Version 1607 for 32-bit Systems 3.0.0.0 < 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0

Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1809 for 32-bit Systems 4.7.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0

Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.