.NET Framework Elevation of Privilege Vulnerability
45Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 2.4%
from disclosure to weapon11 days
Published on NVDMay 21
1st PoC+11d
VulnCheck+2027d
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.
To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.
The update addresses the vulnerability by correcting how .NET Framework activates COM objects.
Affected products
Microsoft · Microsoft .NET Framework 3.0 Service Pack 2Microsoft · Microsoft .NET Framework 3.5.1public PoCs found — 3
vulncheckvulncheck.com/xdb/d867e88863fbunverifiedvulncheckvulncheck.com/xdb/59897520e0c8unverifiedvulncheckvulncheck.com/xdb/db8fc8015f3eunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.