VDB

CVE-2026-35433

CVE-2026-35433 PUBLISHED CVSS 7.300000190734863 HIGH

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

EPSS 0.04% · 12.7th percentile

Risk Scores

CVSS v3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C
EPSS Score
0.04%
12.7th percentile

Affected Products

VendorProductVersions
Microsoft.NET 8.08.0.0, 8.0.0, 8.0.0
Microsoft.NET 10.010.0.0, 10.0.0, 10.0.0
Microsoft.NET 9.09.0.0, 9.0.0, 9.0.0
microsoft.net9.0.0, 10.0.0, 8.0.0

Timeline

  • May 12, 2026 PoC Published
  • May 12, 2026 PoC Published
  • May 12, 2026 CVE Published
  • May 13, 2026 PoC Published
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory

References

…and 52 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›