Описание
.NET Framework Elevation of Privilege Vulnerability
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| .NET 8.0 installed on Windows | ||
| .NET 9.0 installed on Windows | ||
| Microsoft Visual Studio 2022 version 17.12 | ||
| Microsoft Visual Studio 2022 version 17.14 | ||
| Microsoft Visual Studio 2026 version 18.7 | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation) | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 R2 | ||
| Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation) | ||
| Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation) |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.8 High
CVSS3
Связанные уязвимости
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
EPSS
7.8 High
CVSS3